A Palo Alto firewall App-ID migration is not complete just because the application still works. The useful question is: does the approved application match the intended application-based rule, and does unwanted traffic stop when the temporary fallback is removed? This guide provides a migration worksheet, rule-order example and acceptance matrix for answering both questions.
The recommended approach is a staged clone-and-observe migration, not a bulk replacement of every port-based rule. Palo Alto Networks documents cloning as the safest migration approach: the application-based clone is placed above the original port-based rule, which remains available for traffic the clone does not match.[1]