Leading enterprises trust cidaas
From SMEs to large international corporations – cidaas protects millions of digital identities across Europe.
The move is decided. Only the destination is open.
Microsoft closed Azure AD B2C to new customers on 1 May 2025 and now positions Microsoft Entra External ID as its successor. Existing tenants keep running, and Microsoft has committed to supporting them until at least May 2030.
That sounds like time. It is the opposite. Microsoft’s CIAM roadmap now runs through External ID, which means the login experience you have in Azure AD B2C today is broadly the one you will still have in 2030 — while passkeys, no-code orchestration, integrated identity verification and agent identities become the baseline everywhere else.
The question was never when the service switches off. It is how many years you are willing to stand still.
From XML policies to visual flows
- ✓ Multiple files, referencing each other
- ✓ No local debugging
- ✓ Specialist skills required
- ✓ Integrations configured, not coded
- ✓ Changed without a deployment
- ✓ Describe it in natural language
The same identity flow, expressed two ways: hand-authored XML policy files that only a specialist can safely touch, versus a visual orchestration that anyone on the team can read and change.
What holds you to Azure AD B2C does not travel with you
Teams have invested heavily in Azure AD B2C, and much of that investment went into work the platform did not do for them. Custom sign-up journeys, claims transformations, identity provider federation, consent capture. Little of it came out of the box. Most of it was written as XML policy files that reference each other, with no local debugging.
That investment is real. It is also why small changes turn into projects. And now it stops paying back.
Because a migration is coming either way. Whether you move to Microsoft’s successor product or to a platform like cidaas, there is no in-place upgrade and no way to carry your custom policies across. Both are a rebuild.
So the only question still open is what you rebuild into.
Why cidaas is the destination
Six things change on day one.
No XML. Identity orchestration with cnips
cnips
connects identity to the systems around it: external APIs, business systems,
verification services, notification providers.
Integrations are orchestrated in one place - configured, versioned and changed
without writing and deploying policy files. Where you want, you can describe
what should happen in natural language.
Nothing to bolt on.
Consent management, progressive profiling,
fine-grained authorization,
ML-based fraud detection and group management are part of the platform -
not separate providers with separate contracts and separate roadmaps.
In Azure AD B2C, each of these is a custom policy, an add-on or a third party.
Since ID Protection was discontinued, Microsoft's own guidance for risk
protection in Azure AD B2C is to integrate a partner provider.
A platform that keeps moving
Passkeys, adaptive MFA, AI agent identity and new authentication methods arrive as part of the managed service. Improvements reach you automatically, without upgrade projects and without a migration to a successor product.
B2B, B2B2C and B2C in one model
Groups, hierarchies and delegated administration, without custom code.
Identity verification built in
The cidaas ID validator verifies real identities directly in the platform, with no separate provider to contract.
Real-world identification.
Link digital and physical identity via QR code and NFC.
Recognized in current analyst reports
cidaas is recognized as an Overall Leader, Product Leader and Innovation Leader in the KuppingerCole Leadership Compass 2026 reports for CIAM, B2B IAM and IGA.
Recognition across all three categories reflects one holistic European identity platform rather than stitched-together point solutions.
cidaas vs. Azure AD B2C
Anyone investing in a platform today should consider the following factors, among others: migration of existing applications, future-proofing, open standards, integrability, and long-term flexibility.
This comparison is provided for informational purposes and refers to Azure AD B2C, not to Microsoft Entra External ID. Ratings reflect native platform capabilities; several of the capabilities above can be extended through custom policies or third-party providers. Whether a solution fits an organization's requirements depends on its specific configuration and use case.
An EU data center is not the same as EU jurisdiction
You are making a platform decision you will live with for a decade. The question is not which product has more features today. It is whose law reaches your customers' identities.
No, I cannot guarantee it.
Anton Carniaux, Director of Public and Legal Affairs, Microsoft France - testifying under oath before the French Senate in June 2025, when asked whether he could guarantee that French citizens' data held by Microsoft would never be passed to US authorities.
Jurisdiction follows the provider, not the server
The US CLOUD Act can compel a US-headquartered provider to disclose data under its control, regardless of which country that data is stored in.
cidaas: a German company under European law
Sovereign European cloud infrastructure, with dedicated German server locations for KRITIS operators, financial services and the public sector.
European identities deserve European solutions. Book a demo
Migration without a password reset
Azure AD B2C does not export password hashes. That constraint applies to every destination, including Microsoft’s own successor product. It is the reason no vendor can honestly promise a silent bulk migration of existing passwords.
cidaas solves it with on-the-fly credential migration. During a defined transition period both systems run in parallel. When a user signs in for the first time, cidaas validates the credentials against your existing Azure AD B2C tenant, then stores the identity in cidaas and serves every subsequent sign-in itself. No forced reset, no cut-off date, nothing your users have to do.
Azure AD
B2C
Old tenant
cidaas
New home
first sign-in moves the credential — no reset, no cut-off
Azure AD
B2C
Old tenant
cidaas
New home
first sign-in moves the credential — no reset, no cut-off
Set up
Your cidaas environment is available immediately. Configure authentication methods, flows and branding to your requirements.
Migrate
User profiles are exported via the Microsoft Graph API. Credentials migrate on the fly as users sign in.
Integrate
Applications are switched over client by client, at your pace, using open standards.
Good to know
Both systems run in parallel throughout the migration. There is no downtime, and end users are not affected at any point.
cidaas has also presented this Azure AD B2C migration approach at the European Identity & Cloud Conference (EIC), organized by KuppingerCole.
SRG: one identity across TV, radio, streaming and online services
Together with cidaas and integration partner SECURIX, SRG replaced fragmented logins with a modern central identity platform spanning its digital services - one account for TV, radio, streaming and online offerings.
More about the EIC Award 2025A central login and consistent user experience across digital services
Adaptive MFA, consent management and modern group functionality
Reduced login friction and support requests, with a future-ready architecture
The future of digital identity starts with the right platform
See how cidaas replaces Azure AD B2C - with sovereignty, orchestration and a platform that keeps moving.
FAQs: Azure AD B2C alternative
New capability development for Microsoft's customer identity portfolio takes place in Microsoft Entra External ID. For organizations planning beyond that support horizon, this is a good time to evaluate cidaas as an actively developed European alternative.
That leaves room to plan: cidaas can assess your existing user flows, custom policies and integrations and work with you on a phased migration plan rather than a single cut-over.
Because a rebuild is required either way, some organizations use the moment to evaluate a destination outside the Microsoft CIAM product line - cidaas is one such alternative.











