Security at a glance: SSRS Reports Migration Wizard runs locally on the customer’s Windows machine. Migration is performed within the customer’s environment using the SSRS SOAP API. Report content is not uploaded to AzureOps. Internet communication is limited to license activation, and offline activation is available when internet access is not permitted.
Security Model #
- Runs locally: The wizard is installed and executed on the customer’s Windows machine.
- Report-server communication: The wizard communicates with the configured SSRS or Power BI Report Server using the SSRS SOAP API.
- Data processing: Report definitions, data sources, subscriptions, and other migration content are processed within the customer’s environment.
- No report-content upload: Standard migration does not require report content to be uploaded to AzureOps or another external service.
Licensing and Internet Connectivity #
- For online activation, the software communicates with the AzureOps licensing server once to activate the license.
- This licensing communication is separate from report-server migration.
- Migration does not require ongoing communication with the AzureOps licensing server.
- If the migration machine cannot access the internet, customers can use the offline activation process on demand.
Credentials and Data Protection #
- Credentials should be supplied through the wizard’s supported connection and credential fields.
- When Remember credentials is selected, relevant source or target connection credentials may be stored locally on the machine where the wizard is installed.
- Customers should protect the migration workstation and restrict access to locally stored credentials.
- File-share subscription credentials are requested only when required by the migration and must be provided by the user.
Data in Transit #
- Report-server migration traffic: The wizard communicates with the configured SSRS or Power BI Report Server through its SSRS SOAP endpoint. When the endpoint is configured with HTTPS, report-server communication, including authentication information and migration requests, is protected in transit by TLS.
- HTTP endpoints: HTTP does not provide transport encryption. Customers should use HTTPS for report-server endpoints whenever supported by their environment and security policy.
- No external report-content transfer: Migration traffic is between the wizard and the configured source or target report server. Standard migration does not send report definitions, data sources, subscriptions, or other migration content to AzureOps.
Optional SRMW File Migration #
SRMW files provide an export and import mechanism for migration information when a direct connection between source and target report servers is not possible. They are not required for a standard server-to-server migration.
- If data-source credentials are updated before exporting, those credentials may be written in plain text inside the generated
.srmwfile. - When an SRMW file contains credentials, treat the file as sensitive and store it only in an approved secure location.
Diagnostics and Support #
- The wizard does not automatically upload migration content or migration logs to AzureOps as part of the normal migration workflow.
- If support requires logs or diagnostic files, customers should share only information approved by their internal security policy.
Customer Security Responsibilities #
- Use accounts with only the permissions required for the selected migration tasks.
- Protect access to the source and target report servers and the machine running the wizard.
- Use HTTPS where it is configured and appropriate for the report-server environment.
- Follow organizational policies for passwords, secrets, backups, exported files, and log retention.
- Review migrated permissions, data-source settings, subscriptions, and schedules before enabling production workloads.
Compliance Considerations #
The wizard’s local execution can help organizations design migration procedures that align with internal data-residency and change-management requirements. However, using the wizard does not by itself constitute certification or compliance with a particular regulation, framework, or customer policy.
Customers are responsible for assessing the complete migration process against their applicable requirements, including workstation security, report-server permissions, credential handling, file storage, retention, licensing, and support-log sharing.
Need More Information? #
For setup and access requirements, see the Prerequisites page. For the migration workflow, see Getting Started.