Migrate Custom Controls External Mfa
In brief
- **Conditional Access**: The new policy evaluated and granted access
What Entra admins need to know
Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.
Validate downstream integrations
If applicable, verify that these scenarios work correctly with external MFA:
Self-Service Password Reset (SSPR): User can reset password using external MFA.PIM role activation: User can activate privileged roles with external MFA.Risk-based policies: Sign-in risk and user risk policies correctly interact with external MFA.Intune device enrollment: Device registration completes with external MFA.
Full rollout
@@ -316,14 +316,6 @@ Have each test user (or a representative sample) perform the following steps: - **Conditional Access**: The new policy evaluated and granted access - **MFA requirement satisfied by**: External authentication method (not custom control) -### Validate downstream integrations--If applicable, verify that these scenarios work correctly with external MFA:--- **Self-Service Password Reset (SSPR)**: User can reset password using external MFA.-- **PIM role activation**: User can activate privileged roles with external MFA.-- **Risk-based policies**: Sign-in risk and user risk policies correctly interact with external MFA.-- **Intune device enrollment**: Device registration completes with external MFA. ## Full rollout 