Loading...

Microsoft Entra ID: Retirement of Custom Controls in Conditional Access and migration to External MFA

Microsoft Entra ID: Retirement of Custom Controls in Conditional Access and migration to External MFA

Microsoft Entra ID is retiring Custom Controls in Conditional Access by May 2027, replacing them with External MFA for standardized third-party MFA integration. Administrators must migrate policies by September 2026, updating Conditional Access to use External MFA to ensure continued support and security. What and Why Microsoft Entra ID is retiring Custom Controls in Conditional Access and replacing them with External MFA, a generally available, standards-based integration for third-party multifactor authentication (MFA) providers. External MFA provides a more modern, supported, and standardized authentication experience while enabling organizations to continue using approved third-party MFA solutions with Conditional Access policies. This change helps improve long-term supportability, security, and interoperability. Rollout Schedule Key dates: September 2026: Administrators will no longer be able to create new Custom Controls or modify existing Custom Controls in Conditional Access policies. May 2027: Custom Controls will be fully retired and no longer supported. Impact on Your Organization Who is affected Organizations currently using Custom Controls in Microsoft Entra Conditional Access policies. Administrators responsible for Microsoft Entra ID and Conditional Access management. Organizations not using Custom Controls are not affected and do not need to take action. Platforms/Services Microsoft Entra ID Conditional Access Third-party MFA providers integrated with Microsoft Entra ID What will happen Existing Custom Controls will continue to function until retirement in May 2027. Beginning in September 2026, administrators will no longer be able to create new Custom Controls or modify existing Custom Controls. After retirement in May 2027, Custom Controls will no longer be supported. Organizations using Custom Controls must migrate affected Conditional Access policies to External MFA before retirement. No impact is expected for organizations that do not use Custom Controls. Action Required If your organization uses Custom Controls, action is required before May 2027. Recommended actions: Review your Conditional Access policies and identify any policies that use Custom Controls. Configure your third-party MFA provider as an External Authentication Method. Update affected Conditional Access policies to use the standard Require multifactor authentication grant control. Validate authentication flows and confirm successful migration to External MFA. Remove all Custom Control references after migration is complete. Review the […]

The post Microsoft Entra ID: Retirement of Custom Controls in Conditional Access and migration to External MFA appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Entra ID: Retirement of Custom Controls in Conditional Access and migration to External MFA

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Excel: Excel canvas

Excel canvas, a new Copilot feature in Microsoft Excel, creates dynamic reports with visualizations and insights that update automatically wit...

2 days ago

Dynamics 365 Contact Center – Use role-based enforcement for recording and transcription downloads

We are announcing the ability to use role-based enforcement for recording and transcription downloads in Dynamics 365 Contact Center. This fea...

2 days ago

Microsoft Outlook: Right-click to customize the classic ribbon

Microsoft Outlook now allows users to customize the classic ribbon by right-clicking on the Home or View tab to select commands and arrange th...

2 days ago

Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs

Starting October 10, 2026, Exchange Online tenants must configure EWSAllowedAppIDs to allow Exchange Web Services (EWS) access; EWSEnabled=Tru...

2 days ago

Microsoft Entra App Gallery: Self-service onboarding for new applications

Microsoft Entra App Gallery introduces self-service onboarding for new applications, allowing ISVs to validate SSO and provisioning integratio...

2 days ago

Upgraded call history in Teams Calls app

Teams Calls app call history is upgraded to consolidate missed calls and voicemails into single entries and expand history from 100 to 3,000 r...

2 days ago

Power Automate – Enable Process Intelligence Studio in object-centric process mining

We are announcing the availability of Process Intelligence Studio in object-centric process mining in Power Automate Process Mining. This feat...

2 days ago

Dynamics 365 Contact Center – Use after conversation presence status for wrap-up activities

We are announcing the ability to use after conversation presence status for wrap-up activities in Dynamics 365 Contact Center. This feature wi...

2 days ago

Dynamics 365 Finance and Operations cross-app: Migrate finance and operations environments from Lifecycle Services to Power Platform admin center

The self-service environment migration feature moves management of an existing finance and operations apps environment from Microsoft Dynamics...

2 days ago

Microsoft Teams: Start side conversations during meetings

Keep collaboration moving without disrupting the main discussion. Start and continue one-to-one or small-group conversations directly from a m...

2 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.