Blog Post

Microsoft Entra Blog
3 MIN READ

Public preview: External authentication methods in Microsoft Entra ID

Nitika Gupta's avatar
Nitika Gupta
Former Employee
May 02, 2024

Hi folks,

 

Today I’m thrilled to share that the public preview of external authentication methods in Microsoft Entra ID is scheduled for release in the first half of May. This feature will allow you to use your preferred multifactor authentication (MFA) solution with Entra ID.

 

Deploying MFA is the single most important step to securing user identities. A Microsoft Research study of MFA effectiveness showed that the use of MFA reduced the risk of compromise by more than 99.2%! Some organizations have already deployed MFA and want to reuse that MFA solution with Entra ID. External authentication methods allows organizations to reuse any MFA solution to meet the MFA requirement with Entra ID.

 

Some of you might be familiar with custom controls. External authentication methods are the replacement of custom controls, and they provide several benefits over the custom controls approach. These include: 

 

  1. External authentication method integration, which uses industry standards and supports an open model 
  2. External authentication methods are managed the same way as Entra methods 
  3. External authentication methods are supported for a wide range of Entra ID use cases (including PIM activation)

 

I've invited Greg Kinasewitz, Product Manager for Microsoft Entra ID, to tell you more about this new capability.

 

Thanks, and as always, let us know what you think!

 

Nitika Gupta

Group Product Manager

 

--

 

Hi folks,

 

Greg here. I’m super excited to walk you through some of the key capabilities of external authentication methods and readiness from partners. 

 

We’ve heard from some of you about wanting to use another MFA solution along with the power of Entra ID functionality like the rich features of Conditional Access, Identity Protection, and more.  Customers using Active Directory Federation Services (ADFS) with a deployment of another MFA solution have been vocal in wanting this functionality so they can migrate from AD FS to Entra ID. Organizations that are using the Conditional Access custom controls preview have given feedback on needing a solution that enables more functionality. External authentication methods enable your users to authenticate with an external provider as part of satisfying MFA requirements in Entra ID to fill these needs.

 

What are external authentication methods, and how do you use them?

 

External authentication methods can be used to satisfy MFA requirements from Conditional Access Policies, Privileged Identity Management role activation, Identity Protection risk-based polices and Microsoft Intune device registration. They’re created and managed as part of the Entra ID authentication methods policy.  This gives consistent manageability and experience with the built-in methods. You’ll add an external authentication method with the new “Add external method” button in the Entra Admin Center authentication methods management.

 

Figure 1: External authentication methods are added from and listed in authentication methods policies admin experience.

 

When a user is choosing a method to satisfy MFA, external authentication methods are listed alongside built-in methods that the user can use.

 

Figure 2: External authentication methods are shown next to the built-in methods during sign-in.

 

To learn more, check out our documentation.

 

What providers will support external authentication methods?

 

At launch, external authentication methods integrations will be available with the following identity providers. Please check with your identity provider to find out more about availability:

 

 

In addition to the providers that now have integrations in place, external authentication methods is a standards-based open model where any authentication provider that wants to build an integration can do so by following the integration documentation. 

 

We’re super excited for you to be able to start using external authentication methods to help secure your users, and we’re looking forward to your feedback!! 

 

If you want to learn more about these integrations, please visit the Microsoft booth at the RSA Conference next week. There will also be an RSA Conference session hosted by Microsoft Intelligent Security Association (MISA) where Duo will showcase their external authentication methods integration.

  

Register for our webinar on May 15 to learn more about external authentication methods, see demos, and join in the discussion.

 

Learn more about Microsoft Entra  

Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds. 

Updated May 02, 2024
Version 2.0

46 Comments

  • hazardsec's avatar
    hazardsec
    Copper Contributor

    Nitika Gupta, do you know if they will be adding capabilities in the future to allow customers to integrate pre-authentication? This is a capability that exists currently in AD FS with their risk plugin and also in the custom conditional access policies for Azure AD B2C as well as third-party solutions like AWS Cognito. It would be great to know if this is on the roadmap so that we can help customers that are currently relying on AD FS for pre-authentication controls move towards a native Microsoft Entra ID solution.

  • ahttwhite's avatar
    ahttwhite
    Copper Contributor

    hazardsecI am not sure why they didn't mention in the article, but the documentation shows adding an external authentication measure requires "at least a Microsoft Entra ID P1 license." See: https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-external-method-manage

  • hazardsec While it's not visible in my portal I can verify I have been able to add methods through the Graph API. (So, not entirely user-friendly but available.)

  • MikeCrowley's avatar
    MikeCrowley
    Iron Contributor

    Custom Controls were really great for the one DUO shop I worked with that could use it. I'm glad to see this concept has been found and brought back to life. Sadly, Okta isn't on this list. Anyone know if they plan on participating? 

  • hazardsec's avatar
    hazardsec
    Copper Contributor

    I am not seeing this feature available for preview in my account. How do I enable the preview feature? Does it require a P2 license or can it be done with a P1 license?

     

    Ok, sorry, just read first half of May, I thought it was available now 😞

  • ajc196's avatar
    ajc196
    Iron Contributor

    Excellent, thanks!  4 years late is better than never 🙂