Introduction
Microsoft recently published a major update in the Message Center under the identifier MC1422061: the end of Custom Controls in the conditional access policies of Microsoft Entra ID. This feature will be replaced by a modern, standards-based approach called External MFA. This evolution aims to improve the integration of third-party MFA solutions in Entra ID and requires immediate attention if your organization uses these custom controls.
In this article, we detail the implications of this change, the key timeline, and the actions to take to efficiently migrate your policies.

Transition to External MFA
Since 2018, Custom Controls were an integral part of conditional access policies, allowing enterprises to redirect MFA sessions to external providers. However, this mechanism suffered from a lack of native integration with Entra ID features and was not considered a standard MFA solution by Microsoft.
Why External MFA?
Microsoft replaces Custom Controls with a modern, standards-based integration model called External MFA. With this model:
- Third-party MFA providers can be directly integrated into Microsoft Entra ID as a native authentication method.
- Policies using "Require multifactor authentication" benefit from seamless integration.
- User experience is simplified, offering a more consistent interface.
Good to know
External MFA improves back-end management and ensures better robustness of security policies through native integration.
Key dates for migration
Microsoft has defined a two-phase timeline for disabling Custom Controls in conditional access policies:
- September 2026: Last date to make configuration changes. Administrators will not be able to create or modify Custom Controls after this date.
- May 2027: Complete end of Custom Controls. Any remaining dependency on these controls will result in failures in conditional access policies, risking blocking users or bypassing security requirements.
Current limitation
It is important to note that external authentication methods do not yet support "Authentication Strengths" in conditional access policies. Microsoft is actively working on this limitation.
Action plan for administrators
Organizations that do not use Custom Controls do not need to take action. However, if your policies depend on them, here is a guide to implement the transition:
Inventory current policies
Review your existing conditional access policies and identify those that use Custom Controls.
Configure external MFA
Integrate your third-party MFA provider as an external authentication method via the Authentication Methods section of the Microsoft Entra ID portal.
Update existing policies
Once integration is configured, replace the Custom Controls requirement with the standard option Require multifactor authentication in your conditional access policies.
Test and monitor
Thoroughly test the updated policies to verify user experience and ensure compliance with security requirements.

Warning
Any delay in migration could result in service interruptions or reduced security after May 2027.
Additional resources
For detailed instructions on configuring a third-party MFA provider such as Duo Security, see this article: Configure External Authentication Methods in Entra ID with Duo Security.
Microsoft also provides official documentation on this subject:
Conclusion
The replacement of Custom Controls with External MFA modernizes the Microsoft Entra ID ecosystem by offering native integration, improved user experience, and simplified management. Administrators must prepare now for this transition to avoid any impact on security and availability. Get ahead and migrate before the critical deadlines!



