SpyCloud Console Migration
EVERYTHING YOU NEED TO KNOW TO PREPARE FOR YOUR UPGRADED SPYCLOUD EXPERIENCE
Welcome to the SpyCloud Console
If your account is moving from the legacy SpyCloud portal (portal.spycloud.com) to the SpyCloud Console (console.spycloud.com), start here.
This guide explains what's changing, what stays the same, what to expect during migration, and where to go once your account has moved to the SpyCloud Console.
Your move to the SpyCloud Console
All SpyCloud customers are moving to the SpyCloud Console in scheduled waves throughout 2026.
The Console brings your SpyCloud products, exposure data, account settings, and integrations into one place. Everything you rely on today – including your users, watchlists, configurations, and exposure records – moves with you.
SpyCloud will let you know when your account is scheduled to move and what to expect along the way.
| When | What to expect |
|---|---|
| Ahead of your migration (Around 30–45 days before) | We'll share your scheduled migration date and what to expect. |
| On migration day | We'll let you know your migration is underway. Once it's complete, you'll receive a separate welcome email with instructions to sign in and set up your new credentials. |
| 30 days after migration | If you haven't logged in, we'll send a reminder that your Console account is ready. |
Your Customer Success Manager (CSM) and SpyCloud Support are available if you have questions before or after your move.
What changes when you migrate?
The biggest change is where you access and manage SpyCloud. After migration, you'll use the SpyCloud Console instead of the legacy portal. The Console gives you one place to:
- Access your licensed SpyCloud products
- Review identity exposures
- Investigate threats
- Manage users and access
- Connect SpyCloud data to your existing security workflows
Your existing data and configurations move with you, including:
- Users and access
- Watchlists
- Account configurations
- Exposure records
- Historical account activity
Once your migration is complete, you'll use the Console going forward and will no longer have access to the legacy portal.
What do I need to do?
For most users, the first step is simply to watch for migration communications from SpyCloud. We'll tell you when your organization is scheduled to migrate and whether there are any steps you need to take beforehand.
After your migration is complete, you'll receive a Welcome to the SpyCloud Console email with instructions for accessing the Console and setting up your new credentials.
Your welcome link is valid for three days. If it expires before you sign in, contact SpyCloud Support for a new one.
If you're an administrator, your migration communications may include additional steps for authentication, SSO, or onboarding your team.
Products in the SpyCloud Console
What you see in the Console depends on your organization's licenses and your access.
| Product | What it helps you protect | Get started |
|---|---|---|
| Workforce Threat Protection Formerly SpyCloud Employee ATO Prevention | Workforce identities exposed through malware infections, successful phishing attacks, and data breaches | Workforce Threat Protection fundamentals |
| Endpoint Threat Protection Formerly SpyCloud Compass | Identities and access exposed by malware-infected devices, including the potential blast radius across applications | Endpoint Threat Protection fundamentals |
| (NEW) Supply Chain Threat Protection | Identity threats across your third-party and vendor ecosystem | Supply Chain Threat Protection fundamentals |
| Cybercrime Investigations | Uncover hidden identity connections, attribute cybercrime activity, and move from a single indicator to finished intelligence | Cybercrime Investigations fundamentals |
Executive Summary Report
The Console also includes an AI-powered Executive Summary Report that gives you a high-level view of your organization's threats for a selected time frame.
Use the report to compare threats by data source with the previous period, identify top findings, such as risky employees, infected devices, or other threats, review SpyCloud insights and recommended actions, and generate a report for sharing and reporting workflows
See Executive Report.
You can also preview products your organization doesn't currently license through guided demos in the Console.
Find your way around the Console
In addition to your licensed products, the Console includes shared tools and settings for managing your SpyCloud experience.
| Console area | What you can do |
|---|---|
| Source Catalog | See where exposure data came from, including malware logs, successful phishing attacks, breach collections, and combolists. |
| User Management | Invite users and manage access from one place. |
| Assigning Licenses | Control which products users can access. |
| Audit Logging | Review account activity, including historical activity carried over during migration. |
| SSO | Configure single sign-on with Okta, Microsoft Entra ID, ADFS, or a custom SAML or OIDC provider. |
Recommended steps after migration
Once you're in the Console, focus on the areas that affect your team's existing workflows.
-
Review your watchlist. Check the domains, IP addresses, and email addresses you're monitoring and make sure they still reflect what your organization needs to protect. See Managing Your Watchlist.
-
Explore the Source Catalog. Understanding where an exposure came from can help you decide how to investigate and respond. See Exploring and Filtering Sources.
-
Get familiar with SpyCloud data and severity types. Learn how the Console organizes threat data and severity so you can understand what you're seeing and determine what needs your attention. See the Threat Data Guide and Identity Access Records.
-
Review SSO and role-based access control (RBAC). If you manage access for your organization, review your authentication setup and roles as you onboard your team to the Console. See the SSO Guide and RBAC Guide.
-
Check your Audit Log. Get familiar with the Audit Log and use it to review account activity and changes over time. See Audit Logging.
-
Review your API keys. Find your organization's SpyCloud API keys in one place and monitor monthly API usage. See API Guidelines.
Connect SpyCloud data to your security stack
SpyCloud gives you several ways to bring our identity data into the tools and workflows your team already uses.
Integrations
Already using tools such as Splunk, CrowdStrike, or Microsoft Sentinel? Browse the integration catalog within the Console to discover supported integrations and workflows across your security stack.
See the Integration Guide.
Identity Guardians
Identity Guardians help connect SpyCloud data to identity and access workflows in your environment.
Within the Console, you can:
- Download current documentation and software versions for Active Directory Guardian, Entra ID Guardian, and Okta Workforce Guardian
- Review Active Directory Guardian scans and telemetry
- Configure supported session revocation workflows for your cloud identity providers
For Microsoft Entra ID and Okta Workforce environments, see Session Revocation.
API keys
Manage your organization's SpyCloud API keys from Settings > API Keys.
The Console gives you one place to view and manage the keys your organization uses to access SpyCloud APIs across your licensed products. You can also review API usage and find the documentation you need to work with SpyCloud APIs and data schemas.
See API Guidelines.
Migration FAQ
Will I lose any data, users, or configurations?
No. Your users, watchlists, configurations, exposure records, and historical account activity move with your account.
What happened to SpyCloud Employee ATO Prevention and SpyCloud Compass?
These products have new names in the Console:
| Previous name | New name |
|---|---|
| SpyCloud Employee ATO Prevention | Workforce Threat Protection |
| SpyCloud Compass | Endpoint Threat Protection |
Your existing coverage carries forward with the migration.
Can I still access the legacy portal after migrating?
No. Once your migration is complete, you'll no longer have access to the legacy portal. On the day of your migration, we'll let you know when your account has successfully moved. You'll then receive a Welcome to the SpyCloud Console email with instructions for signing in and setting up your new credentials.
Follow the steps in that email to access the Console for the first time.
Will migration change my SpyCloud services?
The migration moves your existing SpyCloud experience to the Console. If you have questions about your organization's specific licenses or services, contact your CSM.
Will there be downtime or a gap in my data?
We don't expect planned downtime as part of your migration. During the migration, some automated integrations may briefly pause while your account moves to the Console. Your historical SpyCloud data moves with you, so you won't lose previously collected data as part of the migration.
Does two-factor authentication only work with Okta?
No. Two-factor authentication isn't limited to Okta. For details about authentication and SSO options in the Console, see the SSO Guide.
How long do I have to use my welcome link?
Your welcome link is valid for three days. If it expires before you sign in, contact SpyCloud Support for a new one.
I already have SSO configured. What changes for me?
Some organizations migrate administrators first so they can configure SSO before the rest of the team is added to the Console. Your migration communications will tell you whether this applies to your organization and what your administrator needs to do.
What to do next
| If you want to... | Here's what to do |
|---|---|
| Prepare for your migration | Watch for your SpyCloud migration communications. They'll include your scheduled date and any steps specific to your account. |
| Migrate sooner | Contact your CSM or SpyCloud Support to request an earlier migration date. |
| Get a guided walkthrough | Contact your CSM or SpyCloud Support to schedule a Console demo. |
Updated about 2 hours ago