CIOPages
Cybersecurity & IdentityHigh Complexity

Buyer's Guide: Customer Identity & Access Management (CIAM)

Compare Okta Customer Identity Cloud (Auth0), Microsoft Entra External ID, Ping Identity, Transmit Security, SAP Customer Data Cloud, Amazon Cognito, Frontegg, and Descope on the one trade-off CIAM lives or dies by — frictionless registration balanced against fraud defense and consent, not the demo of a social-login button.

16 min read 8 vendors evaluated Updated June 2026
Section 1

Executive Summary

Customer Identity & Access Management (CIAM) secures customers, balancing frictionless experience with security and privacy. The choice of CIAM platform, such as Okta Customer Identity Cloud (Auth0), Microsoft Entra External ID, or Ping Identity, depends on navigating the tension between converting customers and preventing fraud and account takeover. The right solution aligns with an organization’s specific needs across these three forces.

CIAM is the only security control your customers see on every visit — which is why it is judged as much on how little it gets in their way as on how many attackers it stops.

Workforce IAM secures people you employ; CIAM secures people you are trying to win. That single difference reorders every priority. The login box is now the front door of the brand, and the buying decision turns on a tension that has no clean answer: every gram of friction you add to registration to keep fraudsters out also costs you real customers at sign-up — and every shortcut you take to convert them invites account takeover, bot fraud, and a privacy regulator’s attention.

This guide provides a vendor-neutral framework for evaluating 8 leading CIAM platforms — Okta Customer Identity Cloud (Auth0), Microsoft Entra External ID, Ping Identity, Transmit Security, SAP Customer Data Cloud, Amazon Cognito, Frontegg, and Descope — across the three forces that actually decide a deployment: frictionless consumer experience (social login, passkeys, passwordless), security at internet scale (bot, fraud, and account-takeover defense), and privacy and consent management. It is written for CISOs, CDOs, product leaders, and the architects who have to make those three pull in the same direction.

The market does not sort into a tidy ranking because the contenders come from different worlds: workforce-IAM suites that extended into customer identity, developer-first auth APIs built for engineering teams, fraud-and-identity platforms aimed at banks, and a customer-data platform that happens to own consent. The right shortlist depends less on a feature grid than on which of those worlds your problem actually lives in.


Section 2

Why Customer Identity Is a Growth Decision, Not Just a Security One

Customer Identity & Access Management (CIAM) matters because it directly impacts revenue, brand reputation, and compliance. Unlike workforce IAM, CIAM outages or clumsy login flows lose sales and erode brands. It’s a strategic decision, increasingly co-owned by the CISO, CDO, and head of digital product, driven by the rise of passkeys, account-takeover fraud, and privacy regimes like GDPR.

CIAM sits on the revenue path in a way almost no other security system does. A workforce IAM outage frustrates employees; a CIAM outage or a clumsy login flow loses sales, abandons carts, and erodes the brand in public. That is why the customer-identity decision is increasingly co-owned by the CISO, the CDO, and the head of digital product — and why it should be framed around customer outcomes, not just control coverage.

🎯
Strategic Impact
Three forces have moved CIAM from an engineering checkbox to a board conversation: passkeys and passwordless are crossing into the mainstream, so the login experience is being rebuilt rather than tuned; automated account-takeover and bot fraud have made the registration and login endpoints the most-attacked surface a consumer brand exposes; and privacy regimes such as GDPR and a thickening patchwork of U.S. state laws now make provable, revocable consent a precondition for using customer data at all. The platform you pick sets the ceiling on all three.

CIAM rarely lives alone. The identity profile it captures — verified, consented, progressively enriched — is frequently the same record that feeds the customer data platform, the marketing stack, and downstream personalization. Whether consent is captured cleanly at the point of registration and then honored everywhere downstream is often the difference between a usable customer record and a compliance liability.

The other 2026 force is non-human identity. The same platforms that authenticate your customers are now being asked to issue scoped, short-lived credentials to first-party APIs, partner integrations, and the AI agents acting on a customer’s behalf. Treat machine and agent identity as a first-class evaluation axis, not a footnote, because it is where the next wave of access risk is concentrating.


Section 3

Should you build or buy Customer Identity & Access Management (CIAM)?

For Customer Identity & Access Management (CIAM), buying is generally recommended over building due to the complexity of features like passkeys, social-IdP quirks, and bot defense, which can quickly create a permanent product team. When buying, choose based on who owns the login and your customer type: standalone CIAM for consumer brands, extending incumbent suites like Okta or Entra, B2B-first CIAM for B2B SaaS, fraud-led identity for high-fraud sectors, or developer-first auth for engineering-led products.

Build-vs-buy is a live question in CIAM in a way it no longer is for workforce identity, because mature auth APIs make rolling your own login tempting — right up until passkeys, social-IdP quirks, bot defense, breached-password screening, and global consent turn it into a permanent product team you never meant to staff. Beyond that, the harder choice is which camp to buy from: a standalone CIAM, customer identity inside a workforce-IAM suite, or a developer-first auth platform. Frame it by who owns the login and what kind of customer you serve, not by the feature checklist.

Scenario Recommendation Rationale
Consumer brand at scale chasing conversion with passkeys and social login Buy standalone CIAM Purpose-built consumer identity gives you progressive profiling, breached-credential screening, and bot defense tuned for sign-up conversion — things a workforce module bolts on late.
Already standardized on a workforce-IAM suite (Okta, Entra, Ping) Extend the incumbent suite Reuse the directory, operations model, and contract before adding a vendor — but pressure-test consumer-scale pricing, consent depth, and login customization against a specialist first.
B2B SaaS needing per-tenant orgs, SSO, and delegated admin Buy B2B-first CIAM B2B identity is a different shape: organizations, tenant isolation, customer-run admin, and just-in-time SSO matter more than a polished consumer sign-up funnel.
High-fraud sector (banking, fintech, marketplace, large retail) Buy fraud-led identity When account takeover is the headline risk, fuse authentication with continuous fraud signals and identity verification rather than scoring risk in a separate, disconnected tool.
Engineering-led product wanting auth as code with full UX control Adopt developer-first auth API-first platforms hand the team primitives and SDKs to own every pixel of the flow — powerful, but you own the orchestration and the upgrade treadmill that comes with it.
Greenfield app on a single hyperscaler with a lean team Start with the cloud-native option A hyperscaler-native service is the fastest start and lowest entry cost, but verify advanced-security and customization limits before consumer volume and fraud risk grow up around it.
⚠️
Common Pitfall
The most expensive CIAM mistake is treating it as an internal IT project and discovering the consumer experience too late. Build login flows reach production fast, then accrete a backlog of passkey edge cases, social-provider breakage, abuse defense, and consent rules until a team is permanently maintaining authentication instead of the product. If you do buy, migrating millions of existing user records — with their hashed passwords, social links, and consent history — is the part that runs long. Plan for coexistence and a staged cutover, not a flag-day switch.

Section 4

How do you evaluate Customer Identity & Access Management (CIAM)?

To evaluate Customer Identity & Access Management (CIAM), weigh key capabilities like Authentication & Login Experience (25%), Fraud, Bot & Account-Takeover Defense (20%), and Privacy, Consent & Preference Management (20%) against your customer mix and risk profile. Also consider Scale, Reliability & Tenancy (15%), Developer Experience & Extensibility (10%), Machine & Agent Identity (5%), and Ecosystem & Commercial Fit (5%). Prioritize platforms that balance experience, security, and consent.

Weight these domains against your own customer mix and risk profile. A privacy-conscious consumer brand and a fraud-heavy fintech will rank them very differently — but every CIAM evaluation should force an explicit trade between experience, security, and consent rather than pretending all three can be maximized at once.

Capability Domain Weight What to Evaluate
Authentication & Login Experience 25% Passkeys/FIDO2 and passwordless as first-class options, breadth of social and federated IdPs, progressive profiling, magic links and OTP, fully brandable hosted and embedded flows, and a frictionless step-up rather than a blanket MFA wall
Fraud, Bot & Account-Takeover Defense 20% Risk-based and adaptive authentication, bot and automation detection on registration and login, credential-stuffing and breached-password protection, behavioral and device signals, and how natively identity verification (IDV) plugs into onboarding
Privacy, Consent & Preference Management 20% Granular, versioned, revocable consent with an auditable trail; preference center; data-residency and regional policy controls; GDPR/CCPA-style data-subject request support; and whether consent propagates to downstream CDP/marketing systems
Scale, Reliability & Tenancy 15% Proven performance at consumer login volumes and traffic spikes, multi-region availability, B2B organization/tenant isolation and delegated administration, and resilience of the authentication service as a revenue-critical dependency
Developer Experience & Extensibility 10% SDK and API quality, hooks/actions/extensions for custom logic, visual or code-based orchestration of identity journeys, environment promotion and versioning, and migration tooling for importing existing users and password hashes
Machine & Agent Identity 5% Issuance of scoped, short-lived tokens for first-party and partner APIs (OAuth client-credentials, M2M), fine-grained authorization (RBAC/ReBAC/ABAC), and emerging support for AI-agent and MCP identities acting on a user’s behalf
Ecosystem & Commercial Fit 5% Pre-built integrations to your app stack and CDP, standards conformance (OIDC, SAML, SCIM, FIDO2), the pricing unit relative to your MAU and growth curve, and the realism of professional-services and support coverage
💡
Evaluation Tip
Instrument the funnel, not the feature. In your evaluation, stand up the real registration and login journey — passkey enrollment, a social provider, a step-up challenge — and measure where users drop and how the platform behaves when you simulate credential-stuffing and bot traffic against it. The vendor that keeps sign-up smooth for a legitimate customer while quietly turning away the attack, and logs a clean consent record while doing it, is the one that wins the trade-off this category is actually about.

Section 5

Which vendors lead in Customer Identity & Access Management (CIAM)?

Consider vendors like Okta Customer Identity Cloud (Auth0), Microsoft Entra External ID, Ping Identity (including ForgeRock), Transmit Security, SAP Customer Data Cloud (Gigya), and Amazon Cognito. The CIAM field splits into camps, so identifying your needs—such as developer-first, Microsoft ecosystem, complex B2B/B2C, fraud prevention, consent management, or AWS-native—is crucial for vendor selection.

8 vendors evaluated — positioning and best fit at a glance
Vendor Positioning Best for
Okta Customer Identity Cloud (Auth0) Leader — Developer + Enterprise Product and engineering teams that want developer-first CIAM with room to scale, especially where one vendor for both customer and workforce identity is attractive
Microsoft Entra External ID Leader — Microsoft Ecosystem Microsoft-aligned organizations that want unified external (B2C + B2B) identity inside the Entra and Azure footprint they already run
Ping Identity (incl. ForgeRock) Leader — Complex B2B/B2C Large enterprises with complex, high-assurance B2B and B2C identity needs and an appetite for orchestration-driven customization
Transmit Security Leader — Fraud + Identity Banks, fintechs, marketplaces, and large retailers where account-takeover and fraud are the headline risk, not an afterthought
SAP Customer Data Cloud (Gigya) Strong — Consent + Profile Consumer enterprises that treat customer identity as the consent-and-profile foundation for marketing, personalization, and data governance
Amazon Cognito Strong — AWS-Native AWS-first engineering teams that want a managed, pay-as-you-go identity service tightly integrated with the rest of their cloud
Frontegg Emerging — B2B SaaS B2B SaaS companies that need tenant-aware identity, delegated administration, and enterprise sign-in features without building them in-house
Descope Emerging — Visual + Agentic Teams that want to design and iterate identity journeys visually — including emerging agentic-identity use cases — without committing everything to code

The CIAM field splits into camps that rarely compete head-to-head. Workforce-IAM leaders — Okta, Microsoft, and Ping — extend an enterprise directory and operating model into customer identity. Fraud-and-identity platforms put account-takeover defense and verification at the center for high-risk consumer businesses. A customer-data platform owns consent and profile as part of the marketing record. Hyperscaler-native services trade depth for proximity to a cloud stack. And developer-first and B2B-first platforms hand engineering teams the primitives to build exactly the experience they want. Most shortlists end up comparing across these camps, which is why naming the camp first matters more than scoring features.

Two recent moves reshaped the field. Thoma Bravo took Ping Identity private in 2022 and, in 2023, acquired ForgeRock and combined it into Ping — so the former ForgeRock Identity Cloud now sits under the Ping brand (being positioned as PingOne Advanced Identity Cloud) alongside PingOne and its DaVinci orchestration. And in late 2025 Twilio acquired developer-first CIAM vendor Stytch, a signal of how strategically the communications and developer-platform players now view customer identity. Verify current ownership and roadmap directly with any vendor before you sign.

Okta Customer Identity Cloud (Auth0)

Leader — Developer + Enterprise

The Auth0 platform under Okta’s name, and the developer experience is still why engineers pick it: clean SDKs, Actions for custom logic, deep extensibility, a broad social and IdP catalog, and enterprise-grade scale, from a long-standing Gartner Access Management Leader that can cover workforce identity from the same vendor. One vendor, two lineages, though — CIAM and workforce identity are still converging, so understand both product histories. MAU-based pricing climbs quickly as consumer volume grows, and Okta’s own past security incidents warrant scrutiny of its identity hygiene before you hand it your customers.

Microsoft Entra External ID

Leader — Microsoft Ecosystem

Microsoft’s next-generation CIAM, generally available since 2024, unifying consumer (B2C) and partner (B2B) external identity on the Entra platform as the strategic successor to Azure AD B2C, with tight ties to the Microsoft cloud, conditional access, and an admin model your team already knows — and Microsoft is a Gartner Access Management Leader. The migration is the live issue: Azure AD B2C closed to new customers in 2025, so existing tenants face a move to External ID, and the newer platform is still maturing some advanced consumer scenarios. Value is strongest when you are already invested in the Microsoft ecosystem.

Ping Identity (incl. ForgeRock)

Leader — Complex B2B/B2C

After the Thoma Bravo combination with ForgeRock, Ping fields one of the deepest portfolios for complex, large-scale identity: PingOne plus DaVinci no-code orchestration, strong API access control, partner and delegated administration, and decentralized-identity capability, from a consistent Gartner Access Management Leader suited to intricate customer journeys. Settle one thing before you sign — which product the roadmap puts you on, since the Ping and former ForgeRock platforms are still converging and PingOne is positioned as go-forward. Breadth brings implementation weight, and private-equity ownership means tracking strategy as it evolves.

Transmit Security

Leader — Fraud + Identity

Fusing authentication with fraud prevention rather than bolting them together is the whole design: passwordless and passkeys backed by behavioral biometrics, device intelligence, and a risk engine built for account-takeover and bot defense, plus identity verification, from a Gartner Access Management Leader clearly oriented toward high-risk consumer use cases. That depth is more capability — and more cost — than a brand that only needs a clean login, so the fit is regulated, fraud-heavy sectors: banks, fintechs, marketplaces, large retailers. A lighter-touch consumer app will not need the full platform.

SAP Customer Data Cloud (Gigya)

Strong — Consent + Profile

This is CIAM as the consented front end of a customer-data strategy rather than as an auth layer. Built on Gigya, it leads with consumer identity tied to enterprise consent and preference management and a profile record designed to feed marketing and customer-data systems, with mature progressive profiling and a consent vault. That framing decides the fit: identity is positioned as part of a broader customer-data and SAP suite, so it shines inside that context and reads as heavier than needed to a team wanting a lightweight developer auth layer. Weigh it against the rest of your martech stack.

Amazon Cognito

Strong — AWS-Native

The closest-to-the-stack option if you are committed to AWS: user pools, social and SAML/OIDC federation, and tiered editions — Lite, Essentials, Plus — that now bring passkeys and passwordless into managed login, with adaptive authentication and compromised-credential detection at the higher tier. Customization and journey orchestration are more limited than purpose-built CIAM, and enabling the advanced security features can raise cost sharply, so model the tier you actually need rather than the one on the pricing page. Outside an AWS commitment the argument mostly disappears.

Frontegg

Emerging — B2B SaaS

Frontegg is built for B2B SaaS specifically, and that focus is the value: multi-tenancy, organization management, customer-run admin portals, SSO, and fine-grained authorization ship as drop-in capability, so your engineers stop rebuilding the enterprise-IT features every buyer demands. Fast to integrate, with a self-service admin experience aimed squarely at SaaS products. The sweet spot is B2B and multi-tenant SaaS rather than mass-market consumer login, consumer-grade fraud tooling is less of a focus than in the fraud-led platforms, and it is an independent venture-backed vendor, so weigh scale and roadmap.

Descope

Emerging — Visual + Agentic

Design the journey, don’t hard-code it — that is the pitch, and the no-/low-code visual flow builder delivers it, composing passwordless, passkey, social, and MFA journeys with per-tenant variations, alongside fine-grained authorization across RBAC, ReBAC, and ABAC. It has moved early on identity for AI agents and MCP servers, issuing scoped, ephemeral credentials, and it remains independent. Visual orchestration is a different working style than code-only auth, ecosystem and connector breadth are still growing against the incumbents, and as a newer entrant it deserves scale references for your volume.

🔎
Market Insight
Customer identity has become contested ground for adjacent platforms, not just identity specialists. Twilio’s 2025 acquisition of Stytch put a communications-and-developer giant into developer-first CIAM; the workforce-IAM leaders keep folding customer identity into their suites; and identity providers are racing to claim the next surface — AI agents and machine identities that authenticate on a customer’s behalf. The decisive question is shifting from “can it do social login and MFA?” — everyone can — to “can it convert a real customer, stop the bot, and prove the consent, all on the same request?”

Section 6

How much should you budget for Customer Identity & Access Management (CIAM)?

CIAM budgeting primarily keys off monthly active users (MAU), with costs escalating for advanced features like passwordless, adaptive security, B2B organizations, or fraud modules. While free or low-cost entry tiers exist, the bill typically moves at the advanced-security tier, not base login. Key cost drivers include MAU volume, plan tiers (e.g., Okta, Microsoft Entra External ID, Ping Identity, Transmit Security, SAP Customer Data Cloud, Amazon Cognito, Frontegg, Descope), and specific module selections.

CIAM pricing almost universally keys off monthly active users (MAU), but the headline rate matters less than the staircase: free or low-cost entry tiers, then step-ups as you add passwordless, adaptive security, B2B organizations, or fraud and verification modules. Model cost against your real MAU curve and the features you will actually switch on, because the advanced-security tier — not the base login — is usually where the bill moves.

Vendor Pricing Model Relative Tier Key Cost Drivers
Okta Customer Identity Cloud (Auth0) Per-MAU subscription, tiered (B2C / B2B plans) Moderate–Premium Active user volume, plan tier, advanced security and attack-protection add-ons, machine-to-machine tokens, enterprise connections
Microsoft Entra External ID Per-MAU, consumption-based within Entra/Azure Lower Monthly active external users, premium features and add-ons, where it sits relative to existing Microsoft agreements
Ping Identity Subscription by MAU / module; suite licensing Premium Module selection (PingOne, DaVinci, Protect, Verify), MAU bands, orchestration and advanced-identity capabilities, deployment model
Transmit Security Platform subscription, typically by MAU / volume Premium Authentication plus fraud-prevention and identity-verification modules, transaction/risk-signal volume, breadth of the platform enabled
SAP Customer Data Cloud Subscription by registered/active identities Moderate–Premium Identity volume, consent and preference management scope, integration into the broader SAP customer-data suite
Amazon Cognito Per-MAU tiers (Lite / Essentials / Plus), pay-as-you-go Lower MAU after the free allowance, selected tier, whether advanced security (adaptive auth, compromised credentials) is enabled
Frontegg Per-MAU / tenant subscription, plan-based Moderate Active users and tenants, plan tier, entitlement and admin-portal features, SSO/enterprise connections
Descope Per-MAU subscription with a free entry tier Lower–Moderate Monthly active users beyond the free tier, plan level, advanced flows, authorization and agentic-identity capabilities
3-Year TCO Formula
TCO = (MAU Subscription × 36 months) + Advanced Security / Fraud / IDV Modules + Implementation + User & Consent Migration + Custom Login Development + Internal FTE − Avoided Build & Maintenance − Avoided Fraud Losses

Section 7

How long does implementation take for Customer Identity & Access Management (CIAM)?

CIAM implementation typically takes 6-9 months, encompassing several phases. The initial Design & Decide phase spans Months 1-2, followed by Build & Integrate from Months 2-4. Migration and Cut Over occurs between Months 3-6, with the final Harden & Optimize phase taking place from Months 6-9.

Sequence a CIAM rollout around the customer journey and the existing user base, not around the admin console. The two hard parts are migrating millions of existing identities without forcing a mass password reset, and tuning the security controls so they stop attackers without bleeding legitimate sign-ups. Plan for both from the start.

Phase 1
Design & Decide (Months 1–2)

Map the registration, login, recovery, and step-up journeys; define the consent model and where consent must propagate downstream; agree the authentication mix (passkeys, social, passwordless) and the camp you are buying from. Set explicit experience and security targets so the trade-off is a decision, not an accident.

Phase 2
Build & Integrate (Months 2–4)

Stand up the platform, brand the hosted or embedded flows, wire in social and federated IdPs, integrate the app stack and the CDP/marketing systems, and connect identity verification where onboarding assurance is required. Establish environments, versioning, and a promotion path before going near production.

Phase 3
Migrate & Cut Over (Months 3–6)

Import existing users with their password hashes and consent history, run lazy or bulk migration with a coexistence period, and stage the cutover by segment rather than flipping everyone at once. Validate that nobody is forced into an avoidable reset and that consent records survive the move intact.

Phase 4
Harden & Optimize (Months 6–9)

Turn on adaptive and risk-based controls, enable bot and account-takeover defenses, roll out passkeys, and tune thresholds against real traffic and simulated attacks. Watch conversion and fraud together, instrument the funnel, and iterate — CIAM is operated, not finished.


Section 8

What should you ask vendors about Customer Identity & Access Management (CIAM)?

Use this checklist during evaluation to make sure each shortlisted platform covers the capabilities that actually decide a customer-identity deployment — experience, abuse defense, and consent, proven on your own flows.


Questions buyers ask

Frequently asked questions about Customer Identity & Access Management (CIAM)

When should we consider extending our existing Okta or Entra workforce IAM suite for CIAM, rather than buying a standalone solution like Auth0 or Transmit Security?

Extend your incumbent suite if you already standardize on a workforce-IAM suite like Okta or Entra to reuse the directory, operations model, and contract. However, pressure-test consumer-scale pricing, consent depth, and login customization against a specialist like Auth0 or Transmit Security first, especially for high-fraud sectors.

For a B2B SaaS company needing per-tenant organizations and delegated admin, what are the trade-offs between Frontegg and a more general CIAM like Okta Customer Identity Cloud?

Frontegg is built specifically for B2B SaaS, offering multi-tenancy, organization management, and customer-run admin portals. Okta Customer Identity Cloud (Auth0) provides a developer-first CIAM with enterprise-grade scale. The trade-off is Frontegg’s B2B-specific features versus Okta’s broader developer experience and scale, which may be less tailored for B2B’s unique needs.

What are the hidden costs or unexpected pricing factors when choosing Amazon Cognito for a greenfield app on AWS?

While Amazon Cognito offers a low entry cost and pay-as-you-go pricing, unexpected costs can arise from enabling advanced security features like adaptive auth or compromised credentials. These features can raise the cost sharply, so carefully model the specific tier and features you actually need beyond the free allowance and basic MAU tiers.

If we are a high-fraud sector like banking or fintech, why is Transmit Security recommended over a general CIAM like Ping Identity?

Transmit Security fuses customer authentication with continuous fraud prevention and identity verification, which is critical when account takeover is the headline risk. Ping Identity offers a deep portfolio for complex, large-scale identity, but Transmit’s platform is specifically designed to integrate authentication with fraud signals rather than treating them as separate, disconnected tools.

For an engineering-led product team that wants auth as code with full UX control, what’s the downside of adopting a developer-first auth platform compared to a more managed service like Amazon Cognito?

Adopting a developer-first auth platform provides primitives and SDKs for full UX control, but the engineering team owns the orchestration and the upgrade treadmill that comes with it. In contrast, Amazon Cognito is a managed service, offering a faster start and lower entry cost, but with more limited customization and journey orchestration.

Section 9

Related Resources

From the directory

Vendors in this category

Directory listings for the Customer Identity & Access Management (CIAM) space— independent of this guide’s evaluation. Compare profiles in the CIOPages directory, or claim yours.

Athenz Claim
Auth0 (Okta) Claim
Authing Claim
BeyondTrust Claim
CyberArk Claim
Delinea Claim
Frontegg Claim
Browse all in the directory Work at one of these? Claim your listing
The Throughline
One decision facing technology leaders, monthly.

Independent. No sponsorships. Unsubscribe anytime.

Tags:CIAMCustomer IdentityAuth0Okta Customer Identity CloudMicrosoft Entra External IDPing IdentityTransmit SecuritySAP Customer Data CloudAmazon CognitoFronteggDescopePasskeysPasswordlessConsent ManagementAccount Takeover