If your business uses Microsoft Entra Conditional Access and you have a third-party MFA product in the mix, there’s a specific change you do not want to discover during a busy Monday morning.

Microsoft is retiring Conditional Access Custom Controls. That matters because Custom Controls are how many organisations bolted an external MFA step into the sign-in flow.

This post is a practical checklist you can run now, so the retirement becomes a planned change, not a surprise outage.

First, get clear on what’s actually retiring (and when)

Custom Controls are the Conditional Access option that sends a user to an external service during sign-in, then returns them to Entra after that service does its job. Microsoft’s replacement path is External MFA, which is built around external authentication methods you manage in Entra.

The key dates to plan around:

  • September 30, 2026: “retirement” milestone. Microsoft says admins will no longer be able to create new Custom Controls or modify existing ones in Conditional Access policies. That means your “we’ll tweak it later” option goes away.
  • May 2027: end of life. If you still rely on Custom Controls at that point, you’re betting your sign-ins on a feature Microsoft has fully ended.

For most growing businesses, the right move is to set your own internal deadline earlier than Microsoft’s. Give yourself time to test, train, and fix the weird edge cases that only show up in real life.

Checklist: inventory where Custom Controls exist (and what they protect)

Before you pick a migration approach, you need a clean list of where Custom Controls are in play today.

  • Find every Conditional Access policy using a Custom Control. In the Entra admin centre, review your Conditional Access policies and note any policy that uses a custom control as a requirement.
  • Write down the “blast radius” for each policy. For each one, capture:
  • which users and groups are included,
  • which apps (Microsoft 365, Azure portal, VPN app, line-of-business apps) it targets,
  • which conditions matter (locations, device platform, client apps).
  • Identify the business reason, not just the setting. “Requires third-party MFA” is not a reason. A reason sounds like: “Finance needs hardware tokens” or “We must use our existing MFA provider for cyber insurance” or “Contractor access needs a different MFA experience.”
  • Note any Report-only policies. If you are using report-only mode to preview changes, keep those in the list. They often reveal hidden dependencies.

This inventory step is where you’ll usually find at least one “Oh right, that old policy” that nobody remembers owning.

Checklist: map what will break if Custom Controls stop working

When Custom Controls retire, the biggest risk is not the setting itself. It’s the workflows built around it.

Work through these common break points:

  • Admin access paths. Admin portals have their own MFA requirements, and your Conditional Access policies often add additional gates. Confirm how admins sign in today, and what happens if the external step is removed or fails.
  • Legacy or special-case apps. Older apps, service accounts, and odd authentication flows can behave differently when you change the MFA step. Make a list of any app that has a history of “special handling.”
  • Remote access dependencies. If your VPN, firewall, or remote access tool assumes the third-party MFA happens via Custom Controls, you need to confirm the new flow still satisfies the same requirement.
  • User experience and support load. If your external provider is where users enrol tokens, approve prompts, or self-service resets, decide what replaces those day-to-day tasks.

A simple way to keep this grounded is to ask, “If this policy vanished tomorrow, who would be locked out first?” Then test that assumption.

Checklist: inventory your third-party MFA integrations (not just the vendor name)

Two businesses can both “use Duo” and still have totally different setups.

Capture the details so you can choose the right migration path:

  • Which provider is involved. Name the vendor and product, plus who owns the relationship and support contract.
  • Where it’s integrated today. Is it only in Conditional Access Custom Controls, or also in:
  • VPN / firewall MFA,
  • Windows sign-in,
  • privileged access workflows,
  • specific apps.
  • What form factors you rely on. Push prompts, phone call, SMS, hardware tokens, passkeys, something else. This matters because not every method maps cleanly.
  • Any compliance or insurance requirements. If you are required to use phishing-resistant methods, or a specific token type, write that down now.

This is also the moment to check whether your MFA provider supports Microsoft Entra External MFA, and what licensing or prerequisites might apply.

Checklist: pick your migration approach to External MFA

There isn’t one right answer. The best approach depends on why you used Custom Controls in the first place.

Here are the common paths we see:

  • Move to External MFA (external authentication methods) and keep your provider. This is the “keep the third-party, modernise the Entra integration” option. It usually makes sense if you have a strong reason to keep that provider (hardware tokens, existing workflows, contractual requirements).
  • Move to Microsoft Entra MFA and retire the third-party MFA. If the third-party tool is only there because “that’s what we set up years ago,” simplifying can reduce moving parts and support overhead.
  • Run a parallel period on purpose. Microsoft notes that Custom Controls and external MFA methods can operate in parallel while you migrate. Plan a short overlap window so you can test without cutting over everyone at once.

Whatever you choose, make sure you explicitly decide how Conditional Access will “know” MFA happened after the change. That sounds obvious, but it’s where migrations often go sideways.

Checklist: set a September 2026 internal deadline (and work backwards)

Microsoft’s retirement milestone is September 30, 2026. If you aim for that exact date, you’ll be migrating while everyone else is also migrating.

A practical internal target is earlier in September 2026, with time reserved for a rollback plan and a second attempt if needed.

  • Set an internal deadline. For example: “All Custom Controls removed from production policies by September 1, 2026.”
  • Schedule a pilot. Start with a small group that includes at least one person from IT, one from finance, and one frequent traveller.
  • Book time for user comms. Even a good MFA change creates questions. A short heads-up email and a one-page “what to expect” saves a lot of tickets.

Checklist: confirm break-glass access still works (before you touch anything)

When you change sign-in controls, you need a way back in if you make a mistake.

Microsoft’s guidance is to maintain emergency access (break-glass) accounts for scenarios where normal admin accounts can’t be used.

  • Have at least two emergency access accounts. Store access details securely and limit who can use them.
  • Exclude them from Conditional Access policies that could block emergency sign-in. The whole point is that they still work when Conditional Access is the thing that is broken.
  • Test them on a schedule. Not every week, but often enough that you trust they work, and that the credentials are retrievable by the right people.

Also keep in mind Microsoft’s mandatory MFA requirements for admin portals and Azure. Your break-glass plan has to align with those rules, not fight them.

Checklist: keep your audit trail intact (prove what changed, and when)

After an authentication change, you want two things: fewer surprises, and cleaner evidence.

  • Confirm you can see Conditional Access policy changes in audit logs. You should be able to answer: who changed a policy, what changed, and when.
  • Confirm you can investigate sign-in outcomes. When a user says “I can’t log in,” you want sign-in logs that show which Conditional Access policies applied and why access was blocked.
  • Decide how long you retain logs. This is a business decision tied to compliance, insurance, and how far back you realistically investigate incidents.

A calm next step

If you are using Custom Controls today, the safest plan is simple: inventory, choose a path, pilot, then cut over with time to spare before September 2026.

If you would like help mapping your Conditional Access policies, validating an External MFA approach, and confirming break-glass access and audit trails, the Flexnet Networks team can help you run the migration cleanly.

Sources