You plan to migrate just this one azure firewall to the azure panorama or you plan to fully migrate the onprem panorama to azure? For the full migration, I still recommend to export the config and import it to the azure panorama and the job is - except for some minor changes in the config like Mgmt IP - done.
Even if you only want to migrate just one it might be the easiest way like this and then delete the devicegroups and templates you do not need in azure.
What do you mean with automate the migration? You can also write a script in order to read the local config and write everything to the other panorama or use existing automation frameworks, but I think in a migration case this might be more work than export/import - depending on your special plan of the migration.
... View more