This document discusses using an identity provider (IDP) versus AEM for authentication for a business with millions of users. Key advantages of an IDP include: avoiding performance issues from searching AEM for authentication; reducing effort to sync users across instances; enabling single sign-on; and ensuring users' credentials are not lost if the AEM repository fails. The document provides use cases demonstrating these advantages, such as the difficulty of syncing 1 million+ users to a new publisher and performance impacts of checking complex group memberships during authentication. It concludes an IDP would be necessary to support millions of users cost-effectively.