A staged move to managed Keycloak that keeps existing passwords working, keeps your applications matching the records they already hold, and replaces a per-user bill with a plan price.
The call is with an engineer rather than a salesperson. Bring your current setup and we will tell you what moving would involve.
Existing tenants keep running today, so you are in a planning window, and the useful thing to do with it is land a decision well before the last year of support.
| Date | What it means |
|---|---|
| May 1, 2025 | End of sale. Azure AD B2C is no longer available to new customers. Existing tenants keep running. |
| March 15, 2026 | Azure AD B2C Premium P2 discontinued for all customers. Tenants continue on P1. This is a licensing change, not a shutoff. |
| At least May 2030 | Microsoft's stated support floor. It is a minimum, not an announced end date. |
No shutoff date has been announced. Source and detail: Azure AD B2C end of sale and support timeline.
Most of a B2C tenant maps cleanly onto Keycloak. Two things need a plan of their own.
Because B2C will not hand over password hashes, nobody can bulk-copy them, us included. The standard answer is a just-in-time (lazy) migration. B2C keeps running in the background. The first time a user signs in to Keycloak, their password is checked against B2C, and if it is correct Keycloak stores it. From then on that user signs in to Keycloak directly and never notices the change.
Users who sign in with Google, Microsoft or a company identity provider have no password to move. Users who do not come back during the migration window get a password reset email when you retire B2C. A forced reset for everyone is the simpler option if your user base will put up with it.
A dual run means B2C and Keycloak operate together while applications move over in waves.
Sign-up, sign-in, reset, each social provider, each federation and MFA, exercised against Keycloak with test accounts before real users arrive.
Start with a low-risk application, watch error rates and support tickets, then move the next. Every wave has a rollback.
B2C stays available for the just-in-time migration until the number of users still being migrated drops below your threshold, typically 60 to 90 days.
Remaining users get a reset email and the tenant is switched off.
Your databases already key customer records on the B2C object ID. During import, each user's object ID is stored on their Keycloak account as an attribute, and it can be issued in the token your applications receive. Applications keep matching the rows they already hold, so nobody has to re-key a database as part of the move.
A simple tenant with one or two user flows and no custom policies usually moves in three to four weeks. A tenant with custom policies, several enterprise federations and custom claims typically takes two to four months. The user import is quick. The time goes into mapping flows, testing applications and the dual-run window.
Azure AD B2C bills per monthly active user. Skycloak charges for the infrastructure your identity runs on, and users are unlimited on every plan.
| Plan | Price | Clusters included |
|---|---|---|
| Developer | $29 per month | 1 |
| Launch | $149 per month | 1 |
| Business | $599 per month | 2 |
| Enterprise | Custom | 3 or more |
Additional clusters cost more, so the bill grows with the number of environments and regions you run, not with the number of people who sign in. Annual billing takes 20% off. Full detail on pricing.
Our sales reps are normally logged into Microsoft by default. When they log into our application, they're already logged in. It's super fluid.
The call is with an engineer rather than a salesperson. Bring your current setup and we will tell you what moving would involve.