Azure AD B2C migration

Leave Azure AD B2C on your schedule, not Microsoft's

A staged move to managed Keycloak that keeps existing passwords working, keeps your applications matching the records they already hold, and replaces a per-user bill with a plan price.

The call is with an engineer rather than a salesperson. Bring your current setup and we will tell you what moving would involve.

The dates Microsoft has published

Existing tenants keep running today, so you are in a planning window, and the useful thing to do with it is land a decision well before the last year of support.

DateWhat it means
May 1, 2025End of sale. Azure AD B2C is no longer available to new customers. Existing tenants keep running.
March 15, 2026Azure AD B2C Premium P2 discontinued for all customers. Tenants continue on P1. This is a licensing change, not a shutoff.
At least May 2030Microsoft's stated support floor. It is a minimum, not an announced end date.

No shutoff date has been announced. Source and detail: Azure AD B2C end of sale and support timeline.

What moves and what does not

Most of a B2C tenant maps cleanly onto Keycloak. Two things need a plan of their own.

Moves across
  • User profiles and attributes, exported through Microsoft Graph
  • Social sign-in (Google, Microsoft, Apple and others) and enterprise federation, reconfigured as identity providers
  • App registrations, which become OIDC or SAML clients
  • Built-in user flows for sign-up, sign-in, profile edit and password reset, which map to standard Keycloak flows
Needs a plan
  • Password hashes. Azure AD B2C does not export them through Microsoft Graph or any other API.
  • Custom policies (the Identity Experience Framework), which are rebuilt as Keycloak authentication flows. See porting IEF custom policies.

Passwords: just-in-time migration

Because B2C will not hand over password hashes, nobody can bulk-copy them, us included. The standard answer is a just-in-time (lazy) migration. B2C keeps running in the background. The first time a user signs in to Keycloak, their password is checked against B2C, and if it is correct Keycloak stores it. From then on that user signs in to Keycloak directly and never notices the change.

Users who sign in with Google, Microsoft or a company identity provider have no password to move. Users who do not come back during the migration window get a password reset email when you retire B2C. A forced reset for everyone is the simpler option if your user base will put up with it.

Run both side by side

A dual run means B2C and Keycloak operate together while applications move over in waves.

1

Test every flow first

Sign-up, sign-in, reset, each social provider, each federation and MFA, exercised against Keycloak with test accounts before real users arrive.

2

Move applications in waves

Start with a low-risk application, watch error rates and support tickets, then move the next. Every wave has a rollback.

3

Keep B2C as the password check

B2C stays available for the just-in-time migration until the number of users still being migrated drops below your threshold, typically 60 to 90 days.

4

Retire B2C

Remaining users get a reset email and the tenant is switched off.

Your applications keep their records

Your databases already key customer records on the B2C object ID. During import, each user's object ID is stored on their Keycloak account as an attribute, and it can be issued in the token your applications receive. Applications keep matching the rows they already hold, so nobody has to re-key a database as part of the move.

How long it takes

A simple tenant with one or two user flows and no custom policies usually moves in three to four weeks. A tenant with custom policies, several enterprise federations and custom claims typically takes two to four months. The user import is quick. The time goes into mapping flows, testing applications and the dual-run window.

What it costs

Azure AD B2C bills per monthly active user. Skycloak charges for the infrastructure your identity runs on, and users are unlimited on every plan.

PlanPriceClusters included
Developer$29 per month1
Launch$149 per month1
Business$599 per month2
EnterpriseCustom3 or more

Additional clusters cost more, so the bill grows with the number of environments and regions you run, not with the number of people who sign in. Annual billing takes 20% off. Full detail on pricing.

Microsoft sign-in, kept

Our sales reps are normally logged into Microsoft by default. When they log into our application, they're already logged in. It's super fluid.
Dustin Principal Web Developer, Beaulieu Canada
Read the case study

Common questions

Can password hashes be exported from Azure AD B2C?
No. B2C does not expose password hashes through Microsoft Graph or any other API. Passwords move through a just-in-time migration on each user's first sign-in, or through a reset.
Do we have to migrate before 2030?
Microsoft has committed to supporting B2C until at least May 2030 and has not announced a shutoff. There is no need to rush, but a migration takes weeks to months, so it is worth deciding well before the final year.
Will our users notice?
With a just-in-time migration, users sign in with the same email and password as before. The sign-in page can carry your own branding. Users who never return during the migration window get a reset email.

Leave Azure AD B2C on your schedule, not Microsoft's

The call is with an engineer rather than a salesperson. Bring your current setup and we will tell you what moving would involve.

Book a 15-minute call
© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman