.png)
SLH (Small Luxury Hotels) required a modern, scalable, and secure Customer Identity and Access Management (CIAM) solution to streamline user authentication and provide seamless Single Sign-On (SSO) experiences. The migration involved moving existing user accounts and authentication flows from the legacy MySLH system to Auth0 (Okta Customer Identity Cloud – CIC), while ensuring smooth integration with the Hilton Finance Portal.
The goal was to deliver a unified identity platform that preserves user experience, maintains branding consistency, and provides enterprise-grade security through centralized identity management, MFA, and automated lifecycle processes.



Legacy Authentication System: MySLH was managing user authentication internally with limited scalability and no native support for external integrations.
Multiple User Stores: Fragmented user data across MySLH and Hilton systems created synchronization and provisioning issues.
Lack of Seamless SSO: Hoteliers required separate logins for MySLH and Hilton Finance Portal, creating friction.
Security Gaps: Limited MFA options and inconsistent password policies across systems.
Migration Complexity: Around 300–400 existing users needed to be migrated to Auth0 without disrupting daily business operations.
Manual Provisioning: User onboarding/deactivation into Hilton Finance Portal relied on manual or semi-manual processes through SailPoint.
Centralized Identity in Auth0 CIC: Migrated all eligible MySLH users to Auth0, enabling a single source of truth for authentication.
Bulk and API-based Migration: Leveraged Auth0's Bulk Import API for exporting users from MySLH (with hashed passwords) and importing into Auth0. For incremental migration, User Creation APIs were used to sync users in real-time.
Seamless SSO: Configured SAML-based SSO between Auth0, MySLH, and Hilton Finance Portal (via PingFederate). Users authenticate once and gain access across systems.
Consistent Branding: Custom domains, branded login pages, and tailored error pages ensured SLH's identity was reflected consistently across all authentication journeys.
MFA & Enhanced Security: MFA was enforced for critical flows (password reset, portal access) with additional Hilton-side MFA during Finance Portal login.
Automated Lifecycle Management: Integrated with Hilton SailPoint for real-time provisioning/deprovisioning of accounts, reducing manual overhead.
Transparent User Experience: Users continued to use the same MySLH interface for registration, login, and password management, while Auth0 worked in the background to handle authentication and synchronization.


.avif)




.png)

.png)

.png)
.png)

.png)
.png)


.png)

.png)

.png)
.png)

.png)
.png)



