Welcome to the fourth installment of my summer roundup series. While Microsoft 365 Copilot and AI features have dominated many of the recent headlines, Microsoft has also announced several important changes in Microsoft Entra ID that deserve attention from identity and security administrators.
In this post, I'll highlight two updates related to authentication and access management. One strengthens the security posture of Self-Service Password Reset (SSPR) by requiring users to register authentication methods explicitly, while the other marks the beginning of the end for Custom Controls in Conditional Access as Microsoft transitions organizations to the newer External MFA framework.
Microsoft Entra ID strengthens Self-Service Password Reset verification requirements
Microsoft is making an important security change to Microsoft Entra ID Self-Service Password Reset (SSPR) by requiring users to verify their identity using explicitly registered authentication methods. Today, some users can complete password reset verification using contact information stored in directory attributes, such as phone numbers or email addresses, even if those values were never formally registered as authentication methods. As part of Microsoft's Secure Future Initiative, SSPR will instead rely on user-validated authentication methods, helping ensure password reset requests are verified using trusted identity data.
Organizations using SSPR should review their authentication method registration coverage before enforcement begins. Once the change takes effect, directory attributes such as mobilePhone, businessPhone, and otherMails will no longer be accepted for password reset verification unless they have been explicitly registered as authentication methods. Microsoft notes that approximately 86% of SSPR verifications already use registered methods today, but users who have not registered sufficient authentication methods will be unable to complete password resets and may need administrator assistance. To help reduce disruption, Microsoft will begin prompting affected users to register authentication methods through an SSPR registration campaign starting October 5, 2026.
Microsoft Entra administrators can review authentication method registration coverage through the User registration details page in the Microsoft Entra admin center. Microsoft recommends ensuring that all users, including administrators, have at least one registered authentication method that satisfies the organization's SSPR policy before enforcement begins.
Enforcement begins on November 7, 2026, with General Availability expected between early and mid-November 2026 across commercial, GCC, and GCC High environments. Microsoft recommends reviewing authentication method registration coverage and encouraging users to register their authentication methods before enforcement begins.
More information:
- Password policies and account restrictions in Microsoft Entra ID
- User register security information (My Security Info)
- Secure Future Initiative
Microsoft Entra ID retires Custom Controls in favor of External MFA
Microsoft has announced the retirement of Custom Controls in Microsoft Entra Conditional Access and is encouraging organizations to move to External MFA, a standards-based integration model for third-party multifactor authentication providers. According to Microsoft, External MFA provides a more modern and supported approach for integrating approved third-party MFA solutions with Conditional Access policies, helping improve long-term supportability, security, and interoperability. Existing Custom Controls will continue to function until May 2027, but administrators will no longer be able to create new Custom Controls or modify existing ones beginning in September 2026.
Organizations currently using Custom Controls should begin planning their migration. Microsoft recommends identifying Conditional Access policies that rely on Custom Controls, configuring third-party MFA providers as External Authentication Methods, and updating affected policies to use the standard Require multifactor authentication grant control. Organizations that do not use Custom Controls are not affected by this change.
September 2026 marks the point at which Custom Controls become read-only, while full retirement is scheduled for May 2027.
More information:
That concludes the fourth installment of this summer roundup series. Both of these updates are part of Microsoft's broader effort to modernize identity security and authentication experiences while aligning with long-term security initiatives such as the Secure Future Initiative.
If your organization relies on Self-Service Password Reset, Conditional Access, or third-party MFA integrations, now is a good time to review your current configuration and begin planning for the upcoming changes.
Thanks for taking the time to read. If you'd like to stay up to date with Microsoft 365, Microsoft Entra, security, compliance, and Copilot-related announcements, you can follow me on LinkedIn
.png)
Comments