
Product Manager @ Microsoft 👉 Sign up to Entra.News my weekly newsletter on all things Microsoft Entra | Creator of cmd.ms & idPowerToys.com
In a recent YouTube episode hosted by Merill Fernando, Microsoft Principal Product Manager Andres Canello walks viewers through the open-source toolkit Migrate2GSA and its role in moving Secure Service Edge configurations into Entra Global Secure Access. The conversation frames migration not as a clean-slate rebuild but as an intentional process that preserves policy intent while automating repetitive work. Consequently, the video stresses balance: accelerate the boring 80 percent, and keep people in control for the nuanced 20 percent. This pragmatic angle sets the tone for administrators weighing speed against operational safety.
The toolkit exports configuration from third-party SSE products, converts those settings into a common CSV schema, and gives administrators a deliberate review step before provisioning. Then, approved configurations provision through Microsoft Graph, where safety checks and validation occur. Importantly, the tool does not aim for a fully automatic end-to-end migration; rather, it targets repeatable tasks so teams can focus on exceptions. As a result, organizations can preserve policy intent while reducing manual, error-prone work.
The workflow emphasizes caution: conflicting segments default to “do not provision,” existing applications are skipped, and generated Conditional Access policies remain disabled until reviewed. Moreover, the toolkit deliberately avoids issuing delete calls, which reduces the risk of accidental removals during migration. Alongside these defaults, the video highlights logging, retries, throttling, and Microsoft Graph validation as part of a layered safety approach. Consequently, teams retain control through a human review gate while benefiting from automation for routine conversions.
The episode explains support for a broad range of SSE vendors, including Zscaler, Netskope, Cisco Umbrella, Palo Alto, Citrix NetScaler, and scenarios involving Microsoft Defender for Endpoint. Furthermore, the toolkit handles both migration scenarios and greenfield provisioning, and it offers backup and restore capabilities that consultants can reuse as baselines. Therefore, organizations with diverse deployments can adopt a common migration path rather than building bespoke scripts for each vendor. Still, the video clarifies that Migrate2GSA is a community project maintained by Microsoft employees and not an officially supported product, so teams should plan accordingly.
A notable point in the episode is how specification-driven development enabled AI to generate extensive PowerShell code while preserving predictability and quality. Rather than relying on ad-hoc scripting, the team used precise specs to guide AI, which produced more than 30,000 lines of PowerShell that required human review. Thus, the process demonstrates how clear specifications make AI-assisted development practical and auditable, especially for security-sensitive tasks. In turn, the episode argues that intent and careful handling of edge cases matter more than who typed the code.
Balancing automation with control represents the central tradeoff: more automation speeds migration, yet it increases the risk of misapplied policies if conversion models differ across vendors. For that reason, Migrate2GSA emphasizes conflict detection and a mandatory human review step, which reduces errors but requires operational time and expertise. Additionally, teams must manage API limits, throttling, and differences in how vendors encode policy intent, so planning and testing remain essential. Overall, organizations that pair automated conversion with staged validation and clear rollback paths stand the best chance of efficient, safe migrations.
Microsoft Entra migration guide, Entra Global Secure Access, Microsoft Entra best practices, Entra zero trust migration, Azure AD to Entra migration, secure access migration strategy, Entra identity and access management, enterprise Entra deployment guide