Microsoft is retiring custom controls in Conditional Access and replacing them with external MFA. From September 2026, no new custom controls can be created and existing ones can no longer be edited; in May 2027 the feature is switched off entirely. This affects every company that has plugged a third-party provider such as Duo, RSA or Okta into its policies via custom controls.
What custom controls are – and why they are going
Custom controls were the established way to bring a third-party multifactor solution into a Conditional Access policy: the sign-in was redirected to the provider, which performed the second check. The catch is fundamental – Entra ID never learns the outcome. A custom control therefore does not satisfy the “require multifactor authentication” grant; it sits alongside it as a separate, isolated condition.
External MFA solves this through a standards-based OpenID Connect flow: the provider is registered as an authentication method and returns a genuine MFA claim. The check becomes visible to Entra ID – and usable by everything that builds on MFA.
The timeline at a glance
- September 2026: administrators can no longer create new custom controls or modify existing ones. Controls already in place keep working.
- May 2027: custom controls are fully retired and no longer supported.
- Organisations that do not use custom controls are unaffected and need to take no action.
Why external MFA does more
The move is not merely a compliance chore. Because external MFA returns a native MFA claim, the second check finally shows up in the sign-in logs – until now it simply did not appear there as MFA. On top of that, scenarios become possible that custom controls never supported: risk-based policies in Conditional Access, Privileged Identity Management and device registration through Intune. For companies that have to evidence their controls to auditors or cyber insurers, accurate logging alone is a good reason not to wait until 2027.
How the migration works
You need a Microsoft Entra ID P1 or P2 licence, the Authentication Policy Administrator role, and a Privileged Role Administrator to grant consent for the provider’s application. From your MFA provider you need three values: the application ID, the client ID and the OIDC discovery URL.
- Take stock: document every Conditional Access policy that uses custom controls – including target groups, apps and conditions. Microsoft provides a Graph PowerShell sample for this.
- Register the provider as an external authentication method, targeted at a test group only at first, and deliberately exclude break-glass accounts.
- Register test users for the method and create a test policy using the standard “require multifactor authentication” grant.
- Verify sign-ins to the protected applications, then roll out in stages.
- Finally, remove all references to custom controls from your policies.
What to watch out for
The effort is routinely underestimated, because custom controls tend to be spread across several policies and nobody is quite sure which of them are still actively used. Migrate policy by policy rather than in one sweep. The timing buffer matters too: from September, existing custom controls can no longer be adjusted. Anyone who only then discovers that a policy needs tightening has lost that option and has to migrate anyway. And missing May 2027 means quietly losing MFA enforcement for the affected access – the policy stays in place but no longer does what it was meant to do.
Official Microsoft sources
- Microsoft Learn: Migrate from custom controls to external MFA in Conditional Access
- Microsoft Entra Blog: External MFA in Microsoft Entra ID is now generally available
Which of your Conditional Access policies are affected, and how to make the switch without downtime, is something we assess as part of a Microsoft Security Assessment – get in touch.
What does this mean for your environment?
Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.
