Amazon Cognito
Auth0
Auth0 requires security policies to be written using custom code in their rules engine, which puts security at risk and in the hands of a developer.
Microsoft B2C/Azure AD B2C
Low security CIAM use cases. Their sweet sot is where security is an afterthought and basic authentication (not authorization) is foundational. Their weaknesses revolve around expensive per-auth MFA, a diverging product from their main B2B/B2E offering, and no integrations with O365 and others.
Duo
MSFT internal
OneLogin
Okta wins on
Ping Identity