External MFA is GA: third-party MFA without giving up Conditional Access
Entra ID now officially supports external MFA providers, with Entra still evaluating policy and risk. It's the proper replacement for custom controls.
On this page
Some organisations have a good reason to use a third-party MFA provider: an existing investment, specialist hardware tokens, or regulatory requirements. Until now, the main way to plug one into Entra was custom controls in Conditional Access, which had real limitations. Most importantly, Entra didn't treat the result as genuine MFA.
External MFA, now generally available, makes a third-party provider a proper authentication method. Entra still evaluates Conditional Access and risk, and the external provider performs the second factor.
What's better than custom controls
- Completing external MFA satisfies an MFA requirement in Conditional Access, like any other method.
- It's configured in the authentication methods policy, alongside your other methods.
- Sign-in logs show the external method, so troubleshooting isn't guesswork.
Custom controls (old)
- Didn't satisfy 'Require MFA'
- Configured as a special control in Conditional Access
- Hard to see in logs
External MFA (now)
- Counts as MFA in Conditional Access
- Lives in the authentication methods policy
- Shows clearly in sign-in logs
Moving over
- Check your provider supports Entra external MFA.
- Set it up as a method in the authentication methods policy and target a pilot group.
- Update Conditional Access policies that reference the custom control so they require MFA instead.
- Retire the custom control once everyone has moved.
Testing before you switch
- Pilot with IT users who can tell you exactly what they saw.
- Check sign-in logs show the external method in the authentication details.
- Test the edge cases: mobile apps, desktop Office apps, and the first sign-in on a new device.
- Keep the old custom control in place for everyone else until the pilot is clean.
Planning for the future
External MFA is useful while you depend on a third-party provider. But adding Entra-native passkeys gives you phishing-resistant sign-in with one fewer system to run and pay for. Many organisations will use external MFA as a bridge while they adopt passkeys.
Can users have external MFA and Entra methods at the same time?
Yes. External MFA is one method in the authentication methods policy, so users in scope can also register Entra-native methods such as passkeys.
Does external MFA count as phishing-resistant?
Check how your provider and Entra classify it before using it with authentication strengths that require phishing resistance. Don't assume a hardware token makes the whole flow phishing-resistant.
What happens if the provider is down?
Users who only have the external method can't complete MFA. Keep break-glass accounts excluded and consider a second registered method for critical users.
This post was last checked against Microsoft's documentation over six months ago. The approach should still hold, but check the linked sources for anything that has changed before you act on it.