Cutover rule
Keep the old path available until the new workflow has passed functional, operational, and rollback tests.
A practical sequence for planning, testing, and de-risking a move away from Auth0.
List applications, login methods, enterprise connections, organizations, roles, MFA, social providers, and custom Actions.
Decide between staged, just-in-time, or password-reset migration. Test account linking and duplicate users.
Run test tenants for SAML SSO, SCIM provisioning, org boundaries, MFA recovery, and audit events.
Migrate a low-risk tenant first, instrument auth errors, keep a rollback window, then move connections in cohorts.
Keep the old path available until the new workflow has passed functional, operational, and rollback tests.