Skip to main content
Kumonix - Microsoft Solutions Partner
All articles

Microsoft Is Retiring the Security Controls Your Company Still Relies On

Microsoft is retiring legacy authentication and tightening Entra ID security controls in 2026, impacting companies still relying on older, less secure systems.

Kumonix Team 3 min read

If your Microsoft 365 tenant has been running quietly in the background for the last few years, this is worth ten minutes of your time.

Microsoft is in the middle of a multi-year tightening of how Entra ID (the system that manages logins, security checks, and access for your firm) works. It's not one dramatic switch flip. It's a series of smaller changes landing across 2026, and each one closes a gap that's been sitting open, sometimes for years, in a lot of companies setups.

None of this is being announced with fanfare. It shows up as a line item in Microsoft's admin message centre, gets actioned by whoever manages your tenant, or it doesn't. And when it doesn't, companies find out the hard way, usually when something stops working or when a security review turns up a gap that's been there the whole time.

Here's what's actually changing, and what it means for a firm that isn't running its own dedicated IT security team.

** Legacy authentication is being phased out

Legacy authentication protocols are older ways of signing into Microsoft 365 that don't support modern security checks. No multi-factor authentication. No Conditional Access. If something in your company, an old device, an outdated app, a piece of practice management software, still connects using one of these protocols, it's effectively invisible to your security policies.

This matters more than it sounds like it should. A company can have strong MFA and a well-configured Conditional Access policy and still have a wide-open door, because one connection method bypasses all of it. Attackers know this. Credential stuffing attacks (where stolen username and password combinations are tried against your systems at scale) specifically target legacy authentication because it's the path of least resistance.

If you don't know whether anything in your company still uses legacy authentication, that's the first thing to find out. It's a five-minute check for whoever manages your tenant, and it's the difference between your security policies actually applying and quietly not.

** Custom controls are being retired in favour of External MFA

A lot of companies set up their multi-factor authentication years ago using something called Custom controls, a way of plugging third-party MFA providers into Conditional Access. Microsoft is retiring this. Custom controls stop being supported from 30th September 2026, and reach full end of life in May 2027.

The replacement is called External MFA, a more integrated way of achieving the same thing. Existing setups keep working for now, but the migration needs planning, not scrambling in September.

Here's the part that catches companies out: if your Conditional Access setup was configured once, during your original M365 rollout, and hasn't been touched since, there's a reasonable chance it's using Custom controls without anyone currently at the company knowing that's the mechanism underneath. This is exactly the kind of thing that gets missed when there's no one specifically responsible for reviewing security configuration on an ongoing basis, which is common at companies this size. Nobody's ignoring it. Nobody's looking at it at all.

** Conditional Access will apply more consistently, including during registration

Up until now, Conditional Access policies have mainly governed sign-in. From mid-2026, they'll also apply during credential registration, meaning when someone sets up Windows Hello, registers a new device, or goes through Apple's platform single sign-on process.

For most companies this is a good thing. It closes a gap where someone could register new credentials without the same scrutiny applied to normal sign-in. But it also means policies that were only ever tested against sign-in behaviour might behave differently during registration. If you're not testing Conditional Access changes in report-only mode before they go live, this is a good moment to start.

** Self-service password reset is getting stricter

Self-service password reset (SSPR) lets staff reset their own password using a registered phone number or email, without needing to call IT. Microsoft is tightening what counts as "registered." Going forward, only formally registered recovery methods will work. Phone numbers or emails pulled from the directory but never actually registered by the user will stop being accepted.

This one's easy to miss because it doesn't break anything until it does. A member of staff locked out of their account, unable to reset their own password because their recovery details were never properly registered, calling IT at the worst possible moment. Worth checking now rather than finding out during an actual lockout.

** What this actually means for your company

None of these changes are individually dramatic. That's exactly why they're easy to miss. Each one on its own is a small adjustment. Together, they represent Microsoft closing several years' worth of gaps that attackers have specifically learned to exploit.

The companies that handle this well aren't the ones with the biggest IT department. They're the ones who treat their Microsoft 365 tenant as something that needs occasional review, the same way you'd review an insurance policy or a lease, rather than something that gets set up once and left alone.

If you can't remember the last time anyone looked specifically at your Conditional Access policies, that's worth changing before September.

Happy to talk through what these changes actually mean for your specific setup, no obligation, just a proper look at where things stand.

Next article

Microsoft Teams Phishing: The Impersonation Risk Most Firms Haven't Trained For

Read the next article

Ready to transform your business?

Let's discuss how our Microsoft solutions can drive your business forward. Get a free consultation and discover what's possible.