Microsoft is rolling out critical updates to its identity and access platform, Microsoft Entra ID, aimed at retiring legacy architectures, modernising multi-factor authentication, and tightening onboarding security.

To provide consistent Conditional Access enforcement across all environments, Microsoft is retiring its legacy Custom Controls feature in favour of External MFA. Backed by standard OpenID Connect, this shift allows organisations to seamlessly integrate third-party MFA providers directly into the Entra ID core architecture.

It also offers seamless integration of third-party MFA providers into Conditional Access and removing legacy architecture.

“Together, these changes help ensure that your security policies are applied uniformly and backed by strong, user-verified signals,” Krishnamurthy noted. 

These critical updates target three vectors, including implementing third-party MFA integrations, credential registration, and tightening self-service password reset. 

Custom controls retire September 30, 2026, and reach end of life in May 2027. 

Previously, Conditional Access rules targeting the Register security information user action protected registrations in My Security Info and Microsoft Authenticator, but left a blind spot during initial device setup. Starting the week of July 6, these security policies will strictly apply to Windows Hello for Business provisioning and macOS Platform Single Sign-on registration, closing a long-standing loophole exploited by attackers during onboarding.