Hi Shasha,
Based on Stefan's response, it sounds like support for the dual-token approach is planned through a new version of the SSO module.
In the meantime, I would recommend avoiding any custom token validation logic that assumes a single IAM provider. If your application relies exclusively on the SiemensInsightsHubSingleSignOn module for authentication and authorization, the migration path will likely be much smoother once the updated module becomes available.
From previous IAM migrations, the areas I'd review proactively are:
If none of those have been customized and authentication is fully delegated to the SSO module, I would expect the majority of the migration effort to be handled through the updated module and its configuration.
It would definitely be helpful if the product team could share migration guidance once the new module is released, especially for customers running production applications in Mendix Public Cloud.
Hope that helps while waiting for the official documentation.
A new SSO module which is supporting Mendix 11 and dual token approach is planned.
Please contact Insights Hub customer service if you need more information