Skip to content
Notifications
Clear all

Migrated from Okta to Auth0 - 3 month migration report

6 Posts
6 Users
0 Reactions
1 Views
(@annac)
Reputable Member
Joined: 2 months ago
Posts: 391
Topic starter   [#29383]

Hey everyone! Just wrapped up the migration of our main customer-facing app from Okta to Auth0, and wanted to share a real-world report from the trenches. Our team is about 40 devs/marketers, and we moved around 85k users. The main drivers were developer experience and better marketing stack integrations.

**The Good (What We Love):**
* **Dev Velocity:** The documentation and quickstart guides are fantastic. Our team implemented social logins (Google, LinkedIn) and a custom passwordless email flow in a fraction of the time it would have taken before. The dashboard is just more intuitive for configuring these flows.
* **Rule & Action Flexibility:** This was a game-changer for our marketing team. We now use Actions to seamlessly pipe new user data into our CRM (HubSpot) and send welcome email sequences via our marketing automation platform. Setting up A/B tests for login page copy was also super easy.
* **Cost for External Users:** For our B2C use case, the pricing model made more sense after a certain volume. The granularity in the tiers helped us forecast better.

**The Not-So-Good (Heads Up!):**
* **Dashboard Quirks:** Sometimes, finding a specific setting means you know *exactly* what menu it's buried in. The search isn't always helpful. We ended up bookmarking key config pages.
* **Learning Curve for Advanced Policies:** While basics are easy, designing complex multi-factor authentication or progressive profiling rules required some trial and error. The community forums were a lifesaver here.
* **Logs & Analytics:** The logs are detailed, but creating custom reports for things like "login attempts by source" isn't as straightforward as we'd hoped. We're exploring pushing logs to our own analytics.

**Our Key Workflow Tip:**
If you're doing a migration, **absolutely use the Migration Playbook** Auth0 provides, but also build a parallel test environment. We migrated users in batches based on sign-up date, which let us iron out kinks without affecting everyone. The biggest time-saver was using the `import_users` function with hashed passwords for a seamless transition.

Overall, we're happy with the switch! The team spends less time wrestling with identity and more time building features and integrating growth tools. Would love to hear if others have tackled similar migrations or found clever uses for Actions with email tools like Klaviyo.

Cheers,
Anna


Keep it simple.


   
Quote
(@harryp)
Reputable Member
Joined: 2 months ago
Posts: 279
 

Hi OP, appreciate you sharing your detailed migration report. I'm a community manager for a B2B SaaS company of similar size, and I oversee a platform that uses Auth0 for our external developer portal and Okta internally for employee access. Running both in parallel gives us a pretty clear view of where each shines.

Here's my breakdown based on managing that setup and talking with a lot of our members about their journeys:

**Target Audience & Fit:** Okta feels built for the internal IT admin, while Auth0 feels built for the product developer. If your primary use case is managing employee lifecycles (provisioning from Workday, complex group rules, desktop SSO), Okta is the default for a reason. For a customer-facing app where you need custom login flows and to embed auth into your dev sprints, Auth0's focus wins. It's not that Okta can't do it, but the configuration mental load is higher.
**Real Pricing & The "Gotcha":** For sub-100k external users, Auth0's Active Monthly Users model often undercuts Okta's per-authenticated user model. The hidden cost with Auth0 isn't the price, it's the feature unlock. Needing things like custom email templates, advanced anomaly detection, or certain compliance frameworks can force you into a higher tier unexpectedly. With Okta, you generally get everything but pay more per head from day one.
**Deployment & Ecosystem Friction:** Auth0 has lower friction to *launch*. Their embedded universal login and clear docs get you to a working prototype fast. Okta has lower friction to *integrate* at scale in a mature enterprise stack. Its pre-built connectors for things like SailPoint or ServiceNow and its depth in SCIM provisioning are more battle-tested. Moving 85k users is right in the zone where this starts to matter.
**Support & Escalation:** In my experience, both have knowledgeable support. The difference is in the engagement model. With Okta, you typically have a named CSM and a clearer path to engineering on enterprise plans. With Auth0, support is more ticket-centric unless you're on a high-tier plan, which can slow things down if you hit a gnarly, custom issue during migration.

For your specific case - a customer-facing app where dev velocity and marketing integrations were the main drivers - I think you made the right call moving to Auth0. If you were also needing to manage internal employees with the same identity store or had strict requirements around centralized policy admin, that's when I'd lean toward Okta or recommend keeping them separate.


~Harry


   
ReplyQuote
(@annas)
Honorable Member
Joined: 2 months ago
Posts: 542
 

You've hit on the exact point that made our own migration so frustrating. The feature unlock cost is real and often comes as a nasty surprise mid-project. We chose Auth0 for its developer velocity, only to find that every non trivial compliance requirement or scaling feature sat behind the "Enterprise" paywall.

Our legal team mandated specific language in the consent prompt and required log retention for 7 years. Both required an enterprise sales negotiation. The cost model wasn't just about users, it was about needing to re negotiate our contract to check a box for a compliance auditor. Okta's model is expensive upfront, but the features are generally all there. Auth0 feels like buying a car where the seatbelts and brakes are a separate subscription.



   
ReplyQuote
 danw
(@danw)
Reputable Member
Joined: 2 months ago
Posts: 387
 

The dev velocity is real. That's the main hook they're selling.

But watch the enterprise bait and switch. You mention A/B testing login page copy. Try to modify the legal text on that page, or change the consent language for GDPR. Suddenly you're on a call with sales asking for a 40% uplift to "unlock" the compliance features.

Okta's pricing is a sledgehammer. Auth0's is a thousand papercuts.



   
ReplyQuote
(@alexj)
Honorable Member
Joined: 3 months ago
Posts: 541
 

That's a fantastic, balanced report. Hearing about the marketing team's direct wins with Actions and A/B testing the login page is a use case I don't see highlighted enough. It really underscores that "dev velocity" isn't just for engineers - it unlocks speed for other teams too.

I'm genuinely curious about the dashboard quirks you hinted at. We've found a similar experience where the intuitiveness for *common* tasks is brilliant, but locating a specific, less-used setting (like a particular OIDC claim mapping or a legacy rule setting) can turn into a bit of a scavenger hunt. Did you and your team develop any tricks for navigating that, or was it just a matter of getting used to the new layout?

Also, congrats on the migration! Moving 85k users is no small feat. 😊


Let's keep it real.


   
ReplyQuote
(@devops_dad)
Honorable Member
Joined: 7 months ago
Posts: 543
 

Your point about running both in parallel is super insightful, and it's exactly the setup we landed on after a few painful migrations. The internal IT admin vs product developer split is spot on.

We tried to force Auth0 for employee SSO once. Big mistake. The provisioning workflows just aren't there. Meanwhile, trying to build a slick, branded customer login journey with complex rules in Okta felt like hammering a square peg.

That dual setup is the sweet spot, even if it feels a bit silly paying two invoices. It's like having a work truck and a sports car. You wouldn't use the sports car to haul lumber.


it worked on my machine


   
ReplyQuote