Microsoft has made external multi-factor authentication (MFA) generally available in Microsoft Entra ID, allowing organizations to integrate trusted third-party MFA providers directly into the identity platform while keeping Conditional Access, real-time risk evaluation, and session controls enforced centrally in Entra ID. The feature is built on OpenID Connect (OIDC) and lets administrators manage both native and external MFA methods through Entra ID’s authentication methods policy, including assigning them to specific user groups.
Microsoft said the capability is aimed at enterprises with regulatory, business, or merger-related requirements that need a consistent MFA approach across fragmented environments. The company also said the new framework will replace Entra ID Custom Controls, which are scheduled for deprecation on September 30, 2026; existing configurations will continue to work during a migration period, and Microsoft plans to publish migration guidance before retirement. Microsoft warned that sign-in frequency and session settings should be tuned carefully, noting that excessive reauthentication can increase phishing risk.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft said the older Custom Controls feature in Entra ID will be deprecated as external MFA becomes its replacement. The company set the retirement date for September 30, 2026, and said migration guidance would be published before the feature is retired.
Microsoft announced the general availability of external multi-factor authentication in Microsoft Entra ID, enabling organizations to integrate trusted third-party MFA providers while keeping Conditional Access, risk evaluation, and session controls centralized in Entra ID. The feature is built on OpenID Connect and can be managed through Entra ID authentication methods policies for selected user groups.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.