Entra ID

Azure AD B2C Migration Tools Now Available

3 min read

Summary

Microsoft has released generally available migration tools and guidance to help Azure AD B2C customers move to Microsoft Entra External ID. With Azure AD B2C no longer receiving new features, these new options give IT teams a clearer path to modernize customer identity while reducing migration risk.

Need help with Entra ID?Talk to an Expert

Azure AD B2C migration tools are now available

Introduction

Organizations using Azure AD B2C now have new Microsoft-supported tools to plan and execute a move to Microsoft Entra External ID. This matters because Azure AD B2C is no longer receiving new features, while Microsoft continues investing in External ID as its next-generation customer identity platform.

For IT teams, this is an important signal to start migration planning early rather than waiting for timelines or technical debt to create pressure later.

What’s new

Microsoft announced that the following migration resources are now generally available:

  • Just-in-Time (JIT) migration for progressive user migration during sign-in
  • High-Scale Compatibility (HSC) mode for large-scale or complex environments
  • Migration guidance and architecture blueprint for planning application sequencing, credential migration, and cutover strategy

Microsoft also highlighted recent Entra External ID platform enhancements, including:

  • Email and SMS OTP MFA
  • Social identity providers through browser-delegated flows
  • Native app to web view SSO
  • Sign-in and sign-up with alias
  • Microsoft Entra ID federation with External ID in public preview
  • Self-service password reset with SMS OTP

Choosing between JIT and HSC

The two migration paths support different priorities:

  • JIT migration is best for most organizations that want a cleaner cutover with minimal user disruption
  • HSC mode is designed for high-scale environments, especially those with more than 5 million users or more complex architectural constraints

In short, JIT focuses on simplicity and user experience, while HSC focuses on scale and operational continuity.

Why this matters for administrators

Azure AD B2C remains supported for existing tenants, but Microsoft has made it clear that new innovation is happening only in Entra External ID. For identity and application teams, that means migration is now a strategic planning exercise rather than a future consideration.

External ID also brings benefits beyond feature parity, including:

  • A modern extensibility model that reduces dependence on complex custom policy XML
  • Better integration with the broader Microsoft Entra ecosystem
  • Improved monitoring, diagnostics, and audit capabilities
  • Continued investment in passwordless and fraud protection capabilities

Admins should take a structured approach:

  1. Assess current applications, user populations, integrations, and custom policies
  2. Decide whether JIT or HSC best fits business and technical requirements
  3. Execute a proof of concept in a non-production environment
  4. Validate identity flows, user journeys, and application dependencies
  5. Engage partners if the environment includes complex customizations or large-scale migration needs

Microsoft has also published a qualified migration partner directory for organizations that need implementation support.

Bottom line

The new Azure AD B2C migration tooling gives organizations a clearer path to Microsoft Entra External ID. Starting early will help IT teams reduce risk, preserve user experience, and modernize customer identity on Microsoft’s actively developed platform.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Azure AD B2CMicrosoft Entra External IDidentity migrationcustomer identityJIT migration

Related Posts

Entra ID

Microsoft Entra Passkeys for External IdP App Sign-Ins

Microsoft has made browser-based authentication for external identity providers generally available for supported Microsoft app sign-ins on Android, iOS, and managed macOS. This lets federated Microsoft 365 users use passkeys, FIDO2 security keys, and eligible SSO sessions in apps like Outlook, Teams, and OneDrive, reducing password fallback and embedded web view limitations.

Entra ID

Microsoft Entra Tenant Governance Webinars 2026

Microsoft is promoting upcoming webinars focused on securing multi-tenant environments with Microsoft Entra Tenant Governance, now generally available. The sessions highlight how organizations can detect shadow tenants, apply consistent governance, and build a stronger identity foundation for AI readiness.

Entra ID

Microsoft Entra App Gallery Self-Service Onboarding Preview

Microsoft has launched a public preview of self-service onboarding for new Microsoft Entra App Gallery applications. The new workflow lets publishers validate OIDC, SAML, and provisioning integrations before submission, then create, submit, and track app listings in the Entra admin center, reducing delays and rework.

Entra ID

Microsoft Entra Private Access Replaces VPNs

Microsoft is positioning Entra Private Access as a practical replacement for traditional VPNs, using identity-driven, per-app access instead of broad network tunnels. The guidance outlines a phased migration approach that helps IT teams reduce attack surface, strengthen Zero Trust controls, and simplify remote access operations.

Entra ID

HiBob Microsoft Entra Integration Now Generally Available

Microsoft has announced general availability of HiBob’s native integration with Microsoft Entra, enabling HR-driven identity lifecycle automation for joiners, movers, and leavers. The integration helps IT teams govern provisioning and access changes across hybrid and cloud environments while reducing manual processes and security risk.

Entra ID

Microsoft Entra September 2026: Key Identity Updates

Microsoft Entra's September 2026 updates introduce new tenant governance, user-centric access reviews, lifecycle workflow cloning, and passwordless resource accounts for Teams devices. The release also adds cloud-to-AD provisioning, AI-focused MCP Firewall protections, and important deadlines for MemberOf-based configurations and permission scope changes.