Skip to content
Thoughts on the new...
 
Notifications
Clear all

Thoughts on the new Entra ID External Identities? Cheaper than B2C?

2 Posts
2 Users
0 Reactions
2 Views
(@grafana_knight_shift_2)
Estimable Member
Joined: 2 months ago
Posts: 110
Topic starter   [#16673]

Just got paged because our customer-facing demo portal had an auth outage. Our old B2C tenant hiccuped, again. While I was drinking my third coffee and silencing alerts, I saw the notification about Entra ID External Identities going GA.

So, for those of us who've been using Azure AD B2C for customer/partner access: is this the promised consolidation? The pricing model *looks* like it could be simpler and cheaper for straightforward social/external identity scenarios compared to B2C's custom policy complexity.

From my SRE lens, I'm thinking about:
* **Break-glass for external users:** How does JIT access or emergency admin work here? Is there a clean audit trail for on-call folks?
* **Monitoring:** Can I get decent Prometheus metrics on auth attempts, token issues, failures? Our current B2C dashboard is... a custom nightmare.
* **Migration path:** If it's truly meant to supersede B2C for simpler cases, what's the move? A slow, canary-style user migration? I'm already picturing the Grafana panel comparing auth latency between old and new.

My gut says this is Microsoft trying to simplify the "which external identity product do I use?" flowchart. But for those of us who built intricate B2C user journeys, does External Identities cover enough, or is it only for basic social logins?

Would love to hear from anyone who's stress-tested it under load or has concrete cost comparisons for a large user base. My alert fatigue can't handle another opaque, expensive auth service.

zzz


Sleep is for the weak


   
Quote
(@cipher_blue)
Estimable Member
Joined: 3 months ago
Posts: 132
 

Oh, another "simplification" from Microsoft. They announce consolidation, but in my experience it usually just adds another layer to the support matrix.

You're right to be skeptical about the migration path. It's never a clean cut-over. If this is meant to supersede B2C for "simple" cases, you can bet the custom policy migration will be a Frankenstein's monster of workarounds. Your canary idea is smart, but I'd want to see concrete docs on session compatibility before I'd even start sketching that Grafana panel.

On monitoring and break-glass: if their current B2C dashboard is a custom nightmare, I'm not holding my breath for Prometheus metrics out of the gate. GA usually means the basic reporting is there, but the kind of granular audit trail an SRE needs for a true emergency? That's a v2 feature, if you're lucky.



   
ReplyQuote