I’m currently implementing a silent migration of our customers to Auth0. What happens if an account in the old identity provider has a password that is weaker than the password policies configured in Auth0?
This is not a concern when migrating users, so the password policies configured in Auth0 do not apply to imported users. You can check out more in this article - Password Strength Validation Effect on User Import.
I hope this helps and if you further questions please let me know!
Best regards,
Remus