Azure AD B2C alternative

cidaas – the
sovereign European alternative to Azure AD B2C

Azure AD B2C is closed to new customers, and its successor is not an upgrade. Since you will be rebuilding either way, this is the moment to decide where your customer identities belong for the next decade.

GDPR GDPR compliant
EU-hosted Sovereign EU Hosting
KuppingerCole Overall Leader KuppingerCole Overall Leader
ISO 27001 ISO 27001 certified

Leading enterprises trust cidaas

From SMEs to large international corporations – cidaas protects millions of digital identities across Europe.

Kaufland – cidaas customer
Hornbach – cidaas customer
Takko Fashion – cidaas customer
Europa Park – cidaas customer
ProSiebenSat.1 – cidaas customer
REHAU – cidaas customer
RATIONAL AG – cidaas customer
1. FSV Mainz 05 – cidaas customer
EWE AG – cidaas customer
SachsenEnergie – cidaas customer
Creditplus Bank – cidaas customer
die Bayerische – cidaas customer

The move is decided. Only the destination is open.

2030
SUPPORT TIMELINE
B2C closed to new customers
1 May 2025
Support ends
May 2030

From XML policies to visual flows

AZURE AD B2C IDENTITY EXPERIENCE FRAMEWORK
TrustFrameworkExtensions.xml
1 <TrustFrameworkPolicy PolicyId=“B2C_1A_TrustFrameworkExtensions”>
2 <BasePolicy>
3 <PolicyId>B2C_1A_TrustFrameworkBase</PolicyId>
4 </BasePolicy>
5 <ClaimsProviders>
6 <ClaimsProvider>
7 <TechnicalProfiles>
8 <TechnicalProfile Id=“SelfAsserted-Social”>
9 <OutputClaims>
10 <OutputClaim ClaimTypeReferenceId=“…” />
11
  • Multiple files, referencing each other
  • No local debugging
  • Specialist skills required
MIGRATION
rebuilt, not ported
CIDAAS IDENTITY ORCHESTRATION
Identity event
Identity check
External API
Business system
Consent & data
Done
  • Integrations configured, not coded
  • Changed without a deployment
  • Describe it in natural language

The same identity flow, expressed two ways: hand-authored XML policy files that only a specialist can safely touch, versus a visual orchestration that anyone on the team can read and change.

What holds you to Azure AD B2C does not travel with you

TrustFrameworkExtensions.xml
1
2
3
4
5
6
7
8
9
10
```

Why cidaas is the destination

No XML. Identity orchestration with cnips

cnips connects identity to the systems around it: external APIs, business systems, verification services, notification providers.

Integrations are orchestrated in one place - configured, versioned and changed without writing and deploying policy files. Where you want, you can describe what should happen in natural language.

Nothing to bolt on.

Consent management, progressive profiling, fine-grained authorization, ML-based fraud detection and group management are part of the platform - not separate providers with separate contracts and separate roadmaps.

In Azure AD B2C, each of these is a custom policy, an add-on or a third party. Since ID Protection was discontinued, Microsoft's own guidance for risk protection in Azure AD B2C is to integrate a partner provider.

A platform that keeps moving

Passkeys, adaptive MFA, AI agent identity and new authentication methods arrive as part of the managed service. Improvements reach you automatically, without upgrade projects and without a migration to a successor product.

B2B, B2B2C and B2C in one model

Groups, hierarchies and delegated administration, without custom code.

Identity verification built in

The cidaas ID validator verifies real identities directly in the platform, with no separate provider to contract.

Real-world identification.

Link digital and physical identity via QR code and NFC.

Recognized in current analyst reports

2026 LC Label CIAM
THE Comparison

cidaas vs. Azure AD B2C

Anyone investing in a platform today should consider the following factors, among others: migration of existing applications, future-proofing, open standards, integrability, and long-term flexibility.

Feature
cidaas logo
Azure AD B2C logo
GDPR compliance & EU data residency i As a US-headquartered provider, Microsoft is subject to the US CLOUD Act, which can require the disclosure of data under its control regardless of where that data is stored. cidaas is a German company, who hosts exclusively in the EU.
Sovereign EU hosting (EU + dedicated German locations for KRITIS) i cidaas hosts on sovereign European cloud infrastructure and offers dedicated German server locations for sectors with heightened compliance needs (KRITIS, financial services, public sector).
EU processing of identity & personal data i cidaas processes identity and personal data within the EU. As a US-headquartered provider, Microsoft is subject to the US CLOUD Act, which can require the disclosure of data under its control regardless of where that data is stored.
Passkeys (FIDO2 / WebAuthn) i cidaas includes Passkeys (FIDO2/WebAuthn) from the Standard plan. Azure AD B2C does not offer native passkey support; passkeys require integrating a third-party identity provider via OIDC and custom policies.
from Standard
Passwordless authentication i cidaas offers passwordless authentication from the Pro plan, including Smart Push, QR-code login, Passkeys and biometrics. Azure AD B2C supports email and phone one-time passcodes as passwordless sign-in options.
from Pro
Adaptive MFA i cidaas includes adaptive, risk-based MFA from the Standard plan. In Azure AD B2C, risk-based signals were tied to the Premium P2 tier, which Microsoft has discontinued; all P2 tenants have been moved to P1. Non-risk conditions such as location remain available, and conditional logic is configured through XML-based custom policies rather than a simple configuration.
from Standard
Biometric authentication (Touch/Face ID) i cidaas supports device-native biometrics such as Touch ID and Face ID, both via WebAuthn/FIDO2 and through native device biometrics integration in mobile apps. Azure AD B2C has no native biometric authentication; biometric methods require integrating a third-party identity provider via OIDC and custom policies.
Breadth of methods (16+, incl. Smart Push & QR-code login) i cidaas offers 16+ authentication methods, including OTP, TOTP, push, Smart Push, QR-code login, biometrics and FIDO2/Passkeys. Azure AD B2C covers SMS, email and TOTP through its built-in user flows; additional methods require custom policies or external providers.
Open standards (OIDC, OAuth 2.0, SAML 2.0) i Both providers support OpenID Connect and OAuth 2.0. In Azure AD B2C, federating a SAML identity provider is available only through XML-based custom policies.
Real-world identification (QR/NFC, digital ↔ physical identity) i cidaas links digital and physical identities: users can authenticate in the real world via QR code and NFC, and identity can drive physical access control. Azure AD B2C does not offer real-world identification.
Developer ecosystem, documentation and partner capacity i Azure AD B2C has an extensive body of existing documentation and community content. New developer content, samples and partner enablement are now refocused. cidaas provides technical documentation, SDKs and a growing European developer and partner ecosystem.
Brand maturity & community size i Azure AD B2C is widely known and established in Microsoft-centric environments worldwide. cidaas is an established and growing brand, with particular strength in the European market.
Free tier i Both providers offer a free tier for getting started. Azure AD B2C includes a generous monthly active user allowance, available to existing customers only, as the product is no longer sold to new customers.
Group & multi-tenant management (B2B, B2B2C, delegated administration) i cidaas goes beyond tenant isolation: users belong to groups, and each group can be assigned a type that defines role restrictions. With delegated user administration, hierarchies and custom group-level fields, cidaas models any kind of group – B2B company structures as well as B2C scenarios like Family & Friends – without custom code. Azure AD B2C has no built-in organization model; B2B structures and per-organization roles are modelled through custom attributes and custom policies.
Consent management (GDPR) i cidaas offers integrated, GDPR-compliant consent management where users can transparently view and manage their consent preferences, including versioned policy changes. In Azure AD B2C, consent is captured through sign-up attributes and custom policies; there is no dedicated consent management surface.
Integrated identity verification (IDV) i The cidaas ID validator enables AI-based digital identity verification directly within the platform. Azure AD B2C does not offer integrated IDV – external providers must be connected separately.
Fine-grained authorization (RBAC / ABAC / ReBAC / PBAC + AuthZEN) i cidaas provides fine-grained authorization with multiple native models – RBAC, ABAC, ReBAC and PBAC – and is compatible with the AuthZEN standard. Azure AD B2C does not support roles for consumer accounts; authorization is handled in the application layer.
Identity orchestration (AI-powered, no-code visual flows) i cidaas provides a no-code visual flow designer for user journeys – including AI-powered workflows you can describe in natural language and flows that can embed agents. In Azure AD B2C, anything beyond the built-in user flows is built in the Identity Experience Framework: XML policy files that reference each other, with no local debugging. Even federating a SAML identity provider is available only through custom policies.
AI agent identity / agentic readiness i With cidaas, identity for AI agents is part of the platform, and agents can be embedded directly into orchestration flows. Azure AD B2C has no dedicated AI-agent identity capability.
AI/ML-based fraud & anomaly detection i cidaas applies machine learning to detect suspicious activity, fraud and anomalies – continuously improved as part of the managed platform. In Azure AD B2C, risk-based detection was provided by ID Protection in the Premium P2 tier, which Microsoft has discontinued. Microsoft's own guidance is to integrate a partner provider instead.
Available to new customers i Microsoft has closed Azure AD B2C to new customers. Existing tenants continue to operate, with support committed until at least May 2030. For organizations planning beyond that horizon, a product that is no longer sold is a product whose roadmap has moved elsewhere.
Ongoing platform development i cidaas is developed and operated as one continuously evolving platform – improvements reach customers automatically. New capability development for Microsoft's customer identity portfolio takes place in Microsoft Entra External ID.
Contractual uptime SLA i Both providers offer a contractual uptime SLA.
Support in German and English, European business hours i cidaas provides support in German and English during European business hours, with direct access to the European product team. Microsoft support for Azure AD B2C is delivered through Azure support plans.
Full Support
Partial / Limited
Not Available

This comparison is provided for informational purposes and refers to Azure AD B2C, not to Microsoft Entra External ID. Ratings reflect native platform capabilities; several of the capabilities above can be extended through custom policies or third-party providers. Whether a solution fits an organization's requirements depends on its specific configuration and use case.

An EU data center is not the same as EU jurisdiction

You are making a platform decision you will live with for a decade. The question is not which product has more features today. It is whose law reaches your customers' identities.

No, I cannot guarantee it.

Anton Carniaux, Director of Public and Legal Affairs, Microsoft France - testifying under oath before the French Senate in June 2025, when asked whether he could guarantee that French citizens' data held by Microsoft would never be passed to US authorities.

Jurisdiction follows the provider, not the server

The US CLOUD Act can compel a US-headquartered provider to disclose data under its control, regardless of which country that data is stored in.

cidaas: a German company under European law

Sovereign European cloud infrastructure, with dedicated German server locations for KRITIS operators, financial services and the public sector.

European identities deserve European solutions. Book a demo

Migration without a password reset

Azure AD
B2C

Old tenant

cidaas

New home

first sign-in moves the credential — no reset, no cut-off

Azure AD
B2C

Old tenant

cidaas

New home

first sign-in moves the credential — no reset, no cut-off

1

Set up

Your cidaas environment is available immediately. Configure authentication methods, flows and branding to your requirements.

2

Migrate

User profiles are exported via the Microsoft Graph API. Credentials migrate on the fly as users sign in.

3

Integrate

Applications are switched over client by client, at your pace, using open standards.

Good to know

Both systems run in parallel throughout the migration. There is no downtime, and end users are not affected at any point.

cidaas has also presented this Azure AD B2C migration approach at the European Identity & Cloud Conference (EIC), organized by KuppingerCole.

AWARD-WINNING CUSTOMER SUCCESS STORY

SRG: one identity across TV, radio, streaming and online services

Together with cidaas and integration partner SECURIX, SRG replaced fragmented logins with a modern central identity platform spanning its digital services - one account for TV, radio, streaming and online offerings.

More about the EIC Award 2025

A central login and consistent user experience across digital services

Adaptive MFA, consent management and modern group functionality

Reduced login friction and support requests, with a future-ready architecture

The future of digital identity starts with the right platform

See how cidaas replaces Azure AD B2C - with sovereignty, orchestration and a platform that keeps moving.

FAQs: Azure AD B2C alternative

Microsoft does not use the word deprecated. Azure AD B2C has been closed to new customers since 1 May 2025, the Premium P2 tier and ID Protection have been discontinued for all customers, and Microsoft has committed to supporting existing tenants until at least May 2030.

New capability development for Microsoft's customer identity portfolio takes place in Microsoft Entra External ID. For organizations planning beyond that support horizon, this is a good time to evaluate cidaas as an actively developed European alternative.
No. Existing tenants continue to operate under Microsoft's stated support commitment until at least May 2030. The reason many teams are evaluating now is not an imminent shutdown - it is that the platform no longer receives new capabilities, and that moving to Microsoft's own successor is itself a rebuild rather than an upgrade.

That leaves room to plan: cidaas can assess your existing user flows, custom policies and integrations and work with you on a phased migration plan rather than a single cut-over.
They are separate products. Microsoft Entra External ID is Microsoft's next-generation customer identity platform and the destination its migration guidance points to. It does not support the XML custom policies of the Identity Experience Framework, so advanced Azure AD B2C configurations have to be rebuilt.

Because a rebuild is required either way, some organizations use the moment to evaluate a destination outside the Microsoft CIAM product line - cidaas is one such alternative.
No. Custom policies built in the Identity Experience Framework are specific to Azure AD B2C and are not supported in Microsoft Entra External ID. Whichever platform you move to, those journeys are rebuilt.
Focus on the following strategic dimensions: the capabilities required for your customer identity use cases, the platform's future-readiness and innovation roadmap, as well as digital sovereignty - including data residency, provider jurisdiction and operational control. The comparison above shows how Azure AD B2C and cidaas differ across these areas.
Yes, through on-the-fly migration. Azure AD B2C does not release password hashes, so cidaas validates credentials against your existing system at each user's first sign-in and takes over the identity from there. Both systems run in parallel during the transition and end users are not affected.
Scroll to Top