An Entra GSA migration should not mean throwing away years of useful SSE policy work and rebuilding every application, segment, and rule by hand.
Existing configuration carries hard-won intent: which populations need access, which destinations should be blocked, and which exceptions keep the business running. Migrate2GSA creates a path to preserve the useful parts while making the migration a deliberate cleanup opportunity.
In this episode of Entra.Chat, I spoke with Andres Canello, Principal Product Manager at Microsoft and creator of Migrate2GSA. Andres demonstrates how the open-source toolkit exports configuration from third-party products, converts it into a common CSV schema, gives administrators an intentional review step, and provisions the approved configuration into Global Secure Access through Microsoft Graph.
The goal is not to configure the product end to end or remove human judgment. Andres describes it as a way to accelerate the repetitive 80%. Conflicting segments default to “do not provision,” existing applications are skipped, generated Conditional Access policies remain disabled, and there is no delete API call in the toolkit.
The conversation also covers greenfield provisioning, backup and restore, reusable consultant baselines, and the unusual development story behind more than 30,000 lines of PowerShell. Andres explains why detailed, published specifications produced better AI-generated code than incremental prompting—and why the intent and edge cases in an open-source contribution matter more than who typed the implementation.
Subscribe with your favorite podcast player or watch on YouTube.
About Andres Canello
Andres Canello is a Principal Product Manager at Microsoft, where he works at the intersection of modern identity and Secure Service Edge. Over his 15 years at Microsoft, he was a founding member of the Entra Global Secure Access team, helping shape the product before it launched, and has since guided some of the largest identity and secure-access deployments in the industry, from banks and miners to national governments. He’s the creator of Migrate2GSA, an open-source migration toolkit used by organizations around the world, which he built end-to-end using AI-assisted, spec-driven development.
Sponsored by
Maester Cloud turns every Maester and Microsoft Zero Trust Assessment run into a durable evidence trail. See new failures, fixes, accepted risks, and posture changes across every tenant - without digging through old HTML reports.
Keep 5+ years of tenant history in your chosen Azure region
Compare runs, spot drift, and get change alerts
Become a Founding Supporter for $99/month to fund open-source Maester development, shape the roadmap, and get self-hosted private-preview access plus 10% off hosted for life.
Related Links
Plan and troubleshoot UserPrincipalName changes in Microsoft Entra ID
(mentioned at 04:07)Azure AD Mailbag: Conditional Access Q&A by Andres Canello (mentioned at 06:43)
Migrate2GSA documentation (mentioned at 45:37)
Migrate2GSA source repository (mentioned at 45:37)
Related Entra.Chat Episodes
How to Migrate from Legacy VPNs to Entra Private Access (Real Strategies from a Veteran)
Global Secure Access Explained: Real-World Rollouts, Mistakes, and Best Practices
Identity-Centric Network Security: Entra Global Secure Access Architecture & Benefits
Chapters
00:00 Intro
01:05 Andres Canello's 15 Years in Microsoft Identity
06:43 A Conditional Access Mistake Admins Still Make
11:29 From Early Customer Pilots to Entra GSA
13:21 Why SSE Migrations Should Not Start From Scratch
18:31 Beyond Migration: Backup Restore and Greenfield
23:27 Export Convert Review and Provision
27:02 How Specifications Made AI-Generated PowerShell Work
35:22 Conflict Detection and the Human Review Gate
39:14 Microsoft Graph Provisioning with Safety Built In
43:35 Automating the Repetitive 80 Percent
46:15 Contributing to Migrate2GSA












