Azure AD B2C User Flow migration: password hash handling and active sessions during cutover
0 reputation · 13 Jun 2024, 08:18 UTC
Migration goal
I am planning to migrate a small application to a new Azure AD B2C User Flow without downtime. The documented approach of on-the-fly user import via the Microsoft Graph API, combined with a staged cutover using a new User Flow and gradual traffic redirection, looks workable in principle.
Open concerns
Two behaviors remain unclear to me before I commit to this design. First, password handling: the import path appears to require either preserving the existing password hash store or re-hashing credentials during migration, and the consequences of each option for users who sign in mid-migration are not clear. Second, session continuity: if the old User Flow is disabled too early, active sessions may be terminated, but I have found no defined guidance on how token renewal should be handled for users whose sessions span the cutover.
Assume a current B2C tenant and a low-traffic app where a brief test migration on a copy of the environment is feasible.
Questions
- Does the Graph API on-the-fly import preserve existing password hashes, or must credentials be re-hashed, and what is the fallback for users caught between the two states?
- What token renewal or validation strategy keeps sessions issued by the old User Flow valid until they naturally expire?
- Is there a documented safe point at which the old User Flow can be disabled without terminating active sessions?