
Catalyst is transitioning from Azure AD B2C to Okta Customer Identity Cloud (Auth0) to modernize its Customer Identity and Access Management (CIAM) solution. The initial phase focuses on replacing Azure AD B2C for the Loan Part Exchange (LPX) and CECLution applications, introducing seamless registration, centralized authentication, single sign-on (SSO), multi-factor authentication (MFA), and branded user experiences. Future phases will expand integration to additional applications like Transact and consolidate MFA for all customer touchpoints, ensuring a scalable and secure CIAM ecosystem.



- Branding inconsistencies across Azure B2C login, emails, and application URLs.
- Multiple disjointed registration and Terms & Conditions flows.
- CECLution lacking MFA compared to LPX, creating inconsistent security.
- Dependency on Azure B2C with complexity in migration (passwords cannot be exported).
- High operational overhead in managing multiple identity silos.
Phase 1: Replace Azure AD B2C with Okta CIC (Auth0) for LPX and CECLution:
- Centralized directory and single identity for both apps.
- Fully branded login, error pages, and communication templates.
- Self-service registration, password resets, and profile updates.
- Secure authentication with optional MFA.
- Unified SSO across applications.
- User migration via bulk import or Auth0 APIs, with password reset or lazy migration.
Future Phases:- Expand integration to additional apps (e.g., Transact).- Consolidate MFA into a unified adaptive solution.- Centralize user management and access policies.- Ensure scalability and compliance with evolving security needs.


.avif)




.png)

.png)

.png)
.png)

.png)
.png)


.png)

.png)

.png)
.png)

.png)
.png)



