Your Marketo Instance Is Moving to AWS. Here Is What to Check First

Adobe is moving every Marketo Engage subscription off its own data centres and onto the AWS public cloud. Adobe describes it as all Marketo Engage subscriptions, so this is not one to sit out. It is happening in waves, one pod at a time. The published schedule opens on 8 July and those waves are already marked complete. Every subscription gets a migration window, and during that window Marketo Engage is completely unavailable.

Adobe gives the reason plainly enough: reliability, scalability and speed. The migrations run pod by pod over several months, and Adobe sends an email and an in-app notification roughly 30 days before your window.

That notice is the part worth pausing on. Thirty days is plenty if it reaches the right person. It is not much time at all if it lands in the inbox of someone who left last year, or if the work it triggers has to go through a queue you do not control.

We have been working through these windows with clients over the past few weeks and found that while the technical prep is short, finding the right people is not.

Here is what is happening, and what we would do about it this week.

What Adobe is actually doing

All Marketo Engage subscriptions are moving from a private data centre to the AWS public cloud. It is happening in waves, one pod at a time, and it has been under way since July.

During your window, all Marketo Engage services are unavailable. Landing pages, forms and data collection go offline and a maintenance message is shown in their place. CRM integrations and LaunchPoint services are disabled and should resume automatically afterward, with no action needed from you.

Adobe’s migration guide does not publish an expected duration, but the individual maintenance notices on status.adobe.com do. For the recent Ashburn pod migrations, those notices describe a complete service disruption of approximately three to four hours inside the window. Treat that as an indication rather than a commitment, watch the status page on the day of your instance’s migration, and confirm restoration by testing rather than by the clock.

Step one is a two-minute check

Open Marketo, go to Admin, then My Account, and scroll down to Support Information. The Data center field holds both answers. The letters are your data centre and the numbers are your pod, so AB49 is Ashburn pod 49.

The abbreviations are ab for Ashburn, sj for San Jose, sn for Sydney, lon for London and nld for Amsterdam. Take that pod number to Adobe’s published schedule and find your date. Two things are worth knowing before you do.

Not every pod has a date yet. At the time of writing, the published schedule ran to 25 September and listed Ashburn and Amsterdam pods only. If your pod is not on it, that is not an exemption. Adobe says dates and pod information are added and changed periodically.

Dates move. Several pods that had dates have since been marked as postponed. So this is a page to check weekly rather than read once.

While you are in there, subscribe to status notifications for your own pod. Adobe supports pod-level subscriptions by email or Slack, which is a far more reliable way to hear about your window than waiting for an email to be forwarded internally.

The one item with real lead time is IP allowlisting

If you only act on one thing this week, make it this one.

Adobe’s guidance is to review and update IP allowlists covering login, API access, email sending, web tracking and integrations, and to add the new addresses while leaving your current entries exactly as they are. Nothing gets removed.

The addresses to add depend on your data centre.

  • Ashburn: 54.160.246.246, 54.237.141.197, 52.20.211.99
  • Amsterdam: 34.247.24.245, 18.200.201.81, 54.220.138.65

Adobe’s instruction is to work with your IT department to get them added, and that short phrase is doing a lot of quiet work.

In our experience this is rarely one list in one place. Corporate firewalls. SFTP allowlists on file transfer jobs. Endpoints that receive webhook calls. Network restrictions inside your CRM. Any CDN or reverse proxy that has Marketo configured as an origin. Adobe does not itemise where those allowlists live, so treat that as our list rather than a checklist from the documentation.

Each one can have a different owner and a different ticket queue, and almost none of them are managed by marketing. This is the same problem we wrote about last month, wearing a different costume. The change is small. The discovery is not.

If you use external forms, this one needs a support ticket

This is the item most likely to be missed, because it does not look like a task.

If you embed Marketo forms on non-Marketo pages, then form submission data collected while Marketo Engage is unavailable is at risk during the window. Adobe’s guidance is to contact Adobe Support at least two business days beforehand and provide the Form ID and your subscription’s Munchkin ID.

Two things follow from that. The ticket has a deadline of its own, ahead of the window. And you need Form IDs, which means somebody has to know which forms are embedded where. If that list does not exist today, better to find out now than 48 hours before your window.

What to pause, and what looks after itself

Adobe’s recommendations for the window are straightforward.

  • Avoid creating or updating people, or running anything that modifies person records
  • Do not trigger follow-on processes, since scheduled campaigns are paused
  • Temporarily disable any integrations that send or receive data
  • Avoid data imports and exports, and any major lead generation campaigns

The freeze itself is the easy half. The harder half is the calendar.

Batch sends scheduled into the window. Event and webinar reminder cadences that assume a send goes out on a particular morning. Lead routing with an SLA attached. And anything driven by paid media, because your ad spend does not pause just because your forms are showing a maintenance message.

If your window lands on a Tuesday evening, the question is not only what Marketo is doing. It is what is still pointing at Marketo while it is down.

The questions your security team will ask

Adobe has published its position on where the data lives, and it is worth reading before someone in security or procurement asks you for it.

Personal data sits in Amazon Aurora, replicated six ways across three availability zones inside the region, with a quorum of four copies required to confirm any write. Aurora also runs continuous automatic backups to Amazon S3, which supports point-in-time recovery to any second inside the configured retention window.

Adobe operates under the AWS shared responsibility model. AWS is responsible for the security and availability of the underlying infrastructure, and Adobe is responsible for the security of the data and applications running on it.

The line that will draw the most attention is this one. Adobe states that Marketo’s Aurora deployment currently operates within a single AWS region without cross-region replication, so disaster recovery comes from multi-availability-zone redundancy and continuous backups rather than geographic failover to a second region. Adobe notes this may be evaluated further as its AWS infrastructure matures.

If you carry data residency commitments in customer contracts, or you sit in a regulated sector, put that in front of your security team in September rather than answering it under pressure in December.

Afterwards, verify rather than assume

The migration guide says CRM and LaunchPoint services should resume automatically, and Adobe’s maintenance notices say services will be restored to their expected operational state as quickly as possible once the migration completes. That is usually how it goes. It is still worth confirming, roughly in this order.

  • Login and API authentication
  • Integrations re-enabled, and the CRM sync backlog clearing
  • LaunchPoint services showing as connected
  • Landing pages, forms, Munchkin tracking, and one real form submission end to end
  • Scheduled and recurring campaigns resumed, with no run quietly skipped
  • Webhooks, and any file-based or SFTP flows
  • A small test send, watching for deferrals

None of that takes long. Skipping it is how a quiet failure survives into the following week.

The same lesson, twice in two months

This is the second time in two months that an Adobe platform change turns out to be an inventory question rather than a technical one. The fix is short in both cases. The expensive part is working out what connects to Marketo, how it authenticates, where its credentials live, and who owns it.

So the question we would ask first is the same question:

If your migration window were next Tuesday, could you name every system whose allowlist needs updating, every form whose submissions you would want preserved, and the person who owns each one?

If you can, it will be a quiet evening.

If you cannot, the schedule is published and there is still time. That is a better position than most.

Get the Integration Inventory Template →

Not sure which of these apply to your instance, or want us to run the checks with you?
Picture of Manish Rohilla

Published:

Lead Marketing Solutions Architect, MAC