> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Upgrade to Iru

> Upgrade your existing Kandji account to the Iru platform. Follow the migration steps, understand what changes, and ensure a smooth transition for your team.

<Tabs>
  <Tab title="About">
    Iru is the unified platform that brings together Endpoint, Identity, and Compliance capabilities. It builds on the foundation of Kandji with a fresh interface, enhanced features, and expanded capabilities designed for the complex security and management needs of modern organizations.

    Apple is still our foundation, and managing Apple devices securely remains a top priority. We're just as committed to building best-in-market Apple solutions, with a dedicated team that's growing and focused only on Apple.

    The upgrade to Iru brings several important changes to the platform:

    * **New look and feel**: The navigation interface features updated branding with the Iru logo and jellyfish icon, a new top navigation bar with enhanced search and Iru AI, and a refreshed sidebar design with customizable sections
    * **New support & knowledge base experience**: Iru Support Chat is available directly from the top navigation bar, and the new Support Knowledge Base is now located at [docs.iru.com](https://docs.iru.com)
    * **New domain**: Your tenant URL changes from `{{subdomain}}.kandji.io` to `{{subdomain}}.iru.com`, and the Enrollment Portal link moves from `{{subdomain}}.kandji.io/enroll` to `{{subdomain}}.iru.com/enroll`
    * **New authentication service**: As part of our transition to Iru, we've introduced a new authentication platform that replaces our previous provider. We built it specifically for complex authentication and authorization use cases, and it sets the foundation for advanced features like granular roles, permissions, and fine-grained access controls.
    * **No impact to end users**: End users don't need to take any action at this time. They'll notice a slightly updated login experience during device enrollment and the new enrollment portal domain, but everything else remains the same.

    <Callout icon="calendar-days" color="#4f46e5" iconType="regular">
      As of **April 8, 2026**, Kandji-branded applications on managed devices have been updated to Iru as part of our transition to Iru.

      **What changed**

      * The **bee logo was replaced with the Iru jellyfish** everywhere the Kandji bee was used.
      * **Application names changed** (for example, "Kandji Self Service" → "Iru Self Service").
      * The **manual enrollment portal branding** now uses Iru.

      **Important notes**

      * If you have **scripts, automations, or other utilities** that reference Kandji applications **by name**, update those references to the new Iru application names.
      * This update was applied **automatically to all Iru-managed endpoints**. The change is consistent across customers and **could not be delayed or customized** per device or per tenant.
      * **Communicate with your end users** about the new name and icon so internal expectations stay aligned.
      * For additional details on branding changes, see [Iru Brand Update](/en/iru/platform-overview/iru-brand-update).
    </Callout>

    ### User Interface Changes

    #### Branding and Navigation

    * **New branding**: The Kandji logo and bee icon have been replaced with the Iru logo and jellyfish icon throughout the platform
    * **Enhanced search**: The top navigation bar now includes "Search or ask Iru AI" with keyboard shortcut support (⌘K)
    * **Iru Support Chat**: Access Iru Support Chat via the chat bubble icon in the upper right corner of the top navigation bar, next to Iru AI

    <Frame>
      <img src="https://mintcdn.com/iru/uOFHT3kR1RCNoJxc/assets/media/images/iru-ui-support-bubble.png?fit=max&auto=format&n=uOFHT3kR1RCNoJxc&q=85&s=1a23b91bb920472ad0d84281dc9b648a" alt="Navigation bar showing the chat bubble icon for Iru Support Chat in the upper right corner, next to Iru AI" width="3044" height="1868" data-path="assets/media/images/iru-ui-support-bubble.png" />
    </Frame>

    * **Updated sidebar**: The left navigation sidebar features a refreshed design with new promotional cards highlighting Identity and Compliance features.

    #### Account Menu

    Tenant-wide settings such as **Access**, **Organization**, and **Integrations** now live in the [Account Menu](/en/iru/platform-overview/account-menu). Click the [**Account Menu Button**](/en/iru/platform-overview/account-menu) at the bottom of the left navigation to open it.

    #### Access

    Manage authentication, connection settings, passkeys, and session controls. The **API tokens** tab is also available here. After upgrade, the Access page shows your new configuration; you manage connection settings (social login, native SSO, and SAML) and passkey registration. The upgrade card disappears once the upgrade to Iru is complete.

    #### Customize Sidebar

    Hide or show Endpoint, Identity, and Compliance sections in the sidebar.

    <Frame>
      <img src="https://mintcdn.com/iru/8BYPjuKZa-zyEEf_/assets/media/images/iru-nav-custom-toolbar.png?fit=max&auto=format&n=8BYPjuKZa-zyEEf_&q=85&s=684b5e970b6cc93a8118d71df6294f41" alt="Account menu with Customize sidebar option highlighted" width="562" height="1040" data-path="assets/media/images/iru-nav-custom-toolbar.png" />
    </Frame>

    #### Getting Started

    An onboarding guide that walks you through initial setup by product area. Use the **Endpoint**, **Identity**, and **Compliance** tabs to see recommended tasks. Tasks are listed as to do or done so you can track progress.

    #### Relocated Features

    Several features have moved to new locations:

    * **Activity**: Pulse icon in the top right navigation bar. See [Activity Page](/en/endpoint/devices/activity-page). **[Unified Activity](/en/iru/platform-overview/unified-activity)** is also available in Preview for a cross-product timeline.
    * **Alerts**: Bell icon in the top right navigation bar. See [Global Alerts](/en/endpoint/devices/global-alerts).
    * **Enrollment**: Bottom of the Endpoint menu in the left navigation. See [Getting Started](/en/endpoint/getting-started/getting-started) for enrollment setup.
    * **Organization**: [**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Organization**
    * **Integrations** and **Apple platform settings**: [**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Integrations**. See [SCIM Directory Integration](/en/endpoint/integrations/scim/scim-directory-integration) for the Integrations page and [Apple Integrations Overview](/en/endpoint/settings/apple-integrations/apple-integrations-overview) for Apple platform settings.
    * **Self Service settings**: **Self Service Settings** tab on the Library page. See [Self Service Settings](/en/endpoint/settings/self-service/self-service-settings).

    ### New Domain

    Your tenant URL changes from `{{subdomain}}.kandji.io` to `{{subdomain}}.iru.com`, and the Enrollment Portal link moves from `{{subdomain}}.kandji.io/enroll` to `{{subdomain}}.iru.com/enroll`.

    After you complete the upgrade, you'll need to log in using your new Iru domain. Your old Kandji domain will automatically redirect to the new domain.

    ### Authentication Improvements and Supported Methods

    Iru's new authentication platform supports all your existing connection types, plus passkeys:

    * Custom SAML configurations
    * Microsoft SSO
    * Google SSO
    * Social Login (using email + password + MFA)
    * Passkeys

    <CardGroup cols={1}>
      <Card title="Passkey Support" icon="key">
        Replace username + password + MFA for administrators using standard authentication. You get enhanced security with a smoother login experience.
      </Card>
    </CardGroup>

    ### Impact on Your Users

    #### For Administrators

    You'll need to complete the upgrade process when you're ready. After upgrade completes, you'll be signed out and need to re-authenticate with your new configuration. Log in using your new Iru domain at `{{subdomain}}.iru.com`—your old Kandji domain at `{{subdomain}}.kandji.io` will automatically redirect to the new domain. Once that's done, you'll have access to the new security features and session controls we mentioned earlier.

    #### For End Users

    End users don't need to do anything. The main differences they see are:

    * A slightly updated login experience during device enrollment
    * The Enrollment Portal link for manual enrollment is now `{{subdomain}}.iru.com/enroll` (replacing `{{subdomain}}.kandji.io/enroll`)

    Everything else stays the same.

    ### Frequently Asked Questions

    <AccordionGroup>
      <Accordion title="When do I need to upgrade?">
        You can complete the upgrade when you're ready. The upgrade process is available when you log in to the Iru web app. Switch to the **Upgrade Process** tab above for step-by-step instructions.
      </Accordion>

      <Accordion title="How long does upgrade take?">
        The upgrade process typically takes just a few minutes, depending on your identity provider and number of connections.
      </Accordion>

      <Accordion title="Will this affect my end users?">
        End users don't need to take any action. They'll notice a slightly updated login experience during device enrollment and the new enrollment portal domain (`{{subdomain}}.iru.com/enroll` instead of `{{subdomain}}.kandji.io/enroll`).
      </Accordion>

      <Accordion title="What if I need help with the upgrade?">
        Email [support@iru.com](mailto:support@iru.com) or [contact Iru Support](/en/iru/iru-support/access-to-iru-support) if you need help with the upgrade process or have questions.
      </Accordion>

      <Accordion title="Can I test the new authentication before fully upgrading?">
        The upgrade process includes a review step where you can confirm your settings before completing the transition.
      </Accordion>
    </AccordionGroup>

    <Callout icon="list-check" color="#4f46e5" iconType="regular">
      Ready to upgrade? Switch to the **Upgrade Process** tab above to follow the step-by-step instructions.
    </Callout>
  </Tab>

  <Tab title="Upgrade Process">
    <Warning>
      During the upgrade process, if you get locked out, or have any issues, email [support@iru.com](mailto:support@iru.com) immediately for assistance.
    </Warning>

    When you're ready to upgrade your tenant to Iru, you'll run the upgrade from **Settings** → **Access**. The process walks you through reviewing and reconfiguring your authentication connections for the new platform, then completing the migration. After it finishes, you'll sign back in at your new Iru domain.

    <Note>
      After you complete the upgrade, all active sessions will end—including your own—and you'll need to re-authenticate with your new configuration. Log in using your new Iru domain at `{{subdomain}}.iru.com`.
    </Note>

    <Steps>
      <Step title="Start the Upgrade">
        When you log in to the Iru Endpoint web app, click **Settings** in the left navigation, then select **Access**. You'll see a card prompting you to upgrade to unified authentication. Click **Start migration** to begin.

        <Frame>
          <img src="https://mintcdn.com/iru/FNiUsOXsUJgOfPqG/assets/media/images/2025-11-07_09-52-30.png?fit=max&auto=format&n=FNiUsOXsUJgOfPqG&q=85&s=9f176f52c736a2871a4b4fb3cd79b6c6" alt="Settings Access page showing the Upgrade to unified authentication card with Start migration button" width="1986" height="786" data-path="assets/media/images/2025-11-07_09-52-30.png" />
        </Frame>
      </Step>

      <Step title="Review Your Connections">
        Look over your current authentication setup and configure replacements for SAML, Google, and Microsoft connections. For step-by-step configuration guides for each connection type, please refer to our [Single Sign-On support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on).

        <Warning>
          You're creating a new SSO connection that will replace your existing one. Make sure to either use a new app in your IdP, or update all ACS URLs, Redirect URLs, SSO URLs, and Entity IDs to match the new values. If Standard Authentication isn't enabled, **incorrect configuration could result in getting locked out of your Iru tenant entirely**.
        </Warning>

        <Frame>
          <img src="https://mintcdn.com/iru/PYP901uFFeJeNw5i/assets/media/images/upgrade-to-iru-review-connections.png?fit=max&auto=format&n=PYP901uFFeJeNw5i&q=85&s=c28cd02044b747ad015fec41010020ee" alt="Review connections interface showing current authentication setup with options to configure replacements" width="2122" height="2790" data-path="assets/media/images/upgrade-to-iru-review-connections.png" />
        </Frame>
      </Step>

      <Step title="Set Up Passkeys (if needed)">
        If you currently use email + password + MFA, register a passkey and send passkey invitations to other administrators who also use standard authentication. For more information, see [Passkeys and Social Login](/en/iru/access/passkeys-and-social-login). When finished, click **Continue** to proceed.

        <Tip>
          On macOS, if you or another administrator is prompted for a passkey but the expected one is not listed, open **System Settings > Privacy & Security > Passkeys Access for Web Browsers** and turn on access for the browser in use. Then close and re-open that browser and try authenticating again. If a team member is locked out after a reset, see [Iru Account Recovery](/en/iru/access/iru-account-recovery).
        </Tip>

        <Frame>
          <img src="https://mintcdn.com/iru/PYP901uFFeJeNw5i/assets/media/images/upgrade-to-iru-setup-passkeys.png?fit=max&auto=format&n=PYP901uFFeJeNw5i&q=85&s=72d0d8f923f83abde90603ad03e0904d" alt="Passkey setup interface showing options to register a passkey and send invitations" width="2122" height="1380" data-path="assets/media/images/upgrade-to-iru-setup-passkeys.png" />
        </Frame>

        <Callout icon="arrow-left" color="#4f46e5" iconType="regular">
          You can click **Back** at any time during the upgrade to return to a previous step and make changes.
        </Callout>
      </Step>

      <Step title="Confirm and Complete">
        Review your settings, and click <strong><Icon icon="pen" size={14} style={{ display: 'inline-flex', verticalAlign: 'middle', marginRight: '0.2em' }} /> Make changes</strong> if needed. Once settings are correct, check the box to confirm, then click **Complete migration** to finish the upgrade.

        <Frame>
          <img src="https://mintcdn.com/iru/PYP901uFFeJeNw5i/assets/media/images/upgrade-to-iru-confirm-complete.png?fit=max&auto=format&n=PYP901uFFeJeNw5i&q=85&s=8a799b23ba93b6380d8dad98675d0c96" alt="Confirm and complete upgrade interface showing review options and completion button" width="1954" height="1380" data-path="assets/media/images/upgrade-to-iru-confirm-complete.png" />
        </Frame>
      </Step>

      <Step title="Re-authenticate">
        Once complete, all logged-in administrators will be signed out and need to re-authenticate with your new configuration. Log in using your new Iru domain at `{{subdomain}}.iru.com`—your old Kandji domain at `{{subdomain}}.kandji.io` will automatically redirect to the new domain. The process typically takes just a few minutes, depending on your identity provider and number of connections.
      </Step>

      <Step title="Migrate Active Directory Certificate Services (if configured)">
        If you used **Active Directory Certificate Services (AD CS)** in Kandji, the tenant upgrade does not replace the **legacy** AD CS Connector on your Windows Server. After you sign in to Iru Endpoint, uninstall that Connector on the server, install the **updated** Connector from your **Iru** tenant, and complete registration approval. Follow [Migrating from Kandji to Iru with AD CS](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview#migrating-from-kandji-to-iru-with-ad-cs) in **AD CS Integration: Overview** for the full workflow, including when the integration may still show **Connected** until you remove the legacy package.
      </Step>
    </Steps>
  </Tab>
</Tabs>
