Microsoft has pushed through several changes to how users authenticate into Entra ID during 2026, and a couple of them come with hard deadlines. If you’re responsible for a tenant’s authentication methods policy, here’s what’s actually changing, when it takes effect, and what to migrate to before support runs out.
Quick Facts
- Custom controls (the legacy third-party MFA integration method) are retiring 30 September 2026, with full end-of-life in May 2027
- Synced passkeys reached general availability in 2026, with per-user profile capacity raised from 3 to 10
- Self-service password reset (SSPR) has required explicit method registration since 7 September 2026 — implicit/inherited registration no longer counts
- System-preferred MFA is being extended to more authentication method combinations, nudging users toward the strongest method they have registered
- Conditional Access now supports Agent ID as a first-class principal type, for governing AI agent authentication alongside users and devices
Custom Controls Retirement: What You Need to Do
Custom controls let you redirect authentication to a third-party MFA provider via a Conditional Access policy — a bridge Microsoft built years ago for organisations mid-migration to Entra. That bridge is being dismantled: custom controls stop working for new configurations from 30 September 2026, and any remaining active usage is fully decommissioned by May 2027.
If your tenant still relies on a custom control (commonly seen with legacy third-party MFA products bolted onto Entra), audit your Conditional Access policies now for the “Require approved client app” or custom control grant conditions. The supported replacement is almost always Microsoft’s native MFA — either Microsoft Authenticator, FIDO2 security keys, or the newer synced passkey option below — enforced directly through a standard grant control rather than a redirect.
Synced Passkeys: What Changed
Passkeys stored in Microsoft Authenticator and synced across a user’s devices reached general availability in 2026, and Microsoft raised the per-user capacity from 3 to 10 passkey profiles — enough headroom for someone juggling a work phone, a personal device, and a couple of hardware keys without hitting a wall. Synced passkeys are phishing-resistant and, unlike device-bound passkeys, survive a phone replacement without a re-enrollment ceremony, which is the practical reason adoption has picked up this year.
If you haven’t enabled the passkey (device-bound or synced) authentication method policy in Entra yet, it’s a low-risk addition to run alongside existing methods — it doesn’t force anyone off what they’re already using, it just adds an option.
SSPR Registration Is No Longer Implicit
From 7 September 2026, self-service password reset requires users to have explicitly registered qualifying authentication methods for SSPR specifically — registration for MFA alone no longer implicitly satisfies the SSPR requirement the way it sometimes did before. If your helpdesk has been relying on “they’ve got MFA set up, SSPR will just work,” check that assumption before the change lands, or you’ll see a spike in reset failures and helpdesk tickets. Run a registration campaign ahead of the deadline rather than after.
System-Preferred MFA
System-preferred MFA automatically prompts users with the strongest authentication method they have registered, rather than whichever one happens to be default or was last used. Microsoft has extended the set of method combinations this applies to through 2026, which means the practical effect of registering a stronger method (like a passkey) increases — the system will actually start using it preferentially, not just hold it in reserve.
Action Checklist
- Search Conditional Access policies for any custom control grant conditions and plan a replacement before 30 September 2026
- Enable synced passkeys as an available authentication method if you haven’t already
- Run an SSPR-specific registration push before 7 September 2026, don’t assume MFA registration covers it
- Review system-preferred MFA behaviour in your tenant to confirm it’s nudging users toward your strongest available method
- If you use AI agents against Entra-protected resources, review whether Agent ID—based Conditional Access policies apply to your scenario
For the full picture on hybrid identity, licensing, and getting started with Entra ID overall, see our complete Microsoft Entra ID guide.
Discover more from TechyGeeksHome
Subscribe to get the latest posts sent to your email.