Identity platform for customer-facing apps; since 1 May 2025 new customers can't buy it and are directed to its successor, Microsoft Entra External ID. Tokens it issues can be checked by API Management's validate-jwt policy via its OpenID configuration.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure AD B2C in context, with comparison tables and the common traps.
Terms in this definition
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- Microsoft Entra External ID
Platform for external identities from Microsoft, spanning B2B collaboration and customer (CIAM) tenants. New customers use it in place of Azure AD B2C.
- API Management
Azure's API gateway, where policies like rate limits, quotas, ip-filter and validate-jwt are defined once and apply to every API. Production VNet injection is offered in the Premium tier.
- validate-jwt
Before API Management passes a request on to the back end, this policy confirms the JWT has the expected issuer, audience and claims.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
Related terms
- B2C
Microsoft stopped selling Azure AD B2C to new customers on 1 May 2025. It was the older customer identity (CIAM) offering, now succeeded by Microsoft Entra External ID running in an external tenant.