As part of Microsoft Entra ID, Microsoft has introduced a new approach to managing authentication methods and has gradually retired the legacy settings for multi-factor authentication (MFA) and self-service password reset (SSPR). Organizations using Microsoft 365 must migrate their existing settings to the new management model.
Microsoft began introducing the transition to the new system in 2024 and 2025, when it added a migration tool to Microsoft Entra ID and started notifying users about the upcoming change. Further information is available in the official Microsoft documentation on managing authentication methods.
30 September 2025 marked a key milestone, as the legacy MFA and SSPR policies were officially deprecated. The management of authentication methods was transferred to the new Authentication Methods policy.
This change is required by Microsoft. Its purpose is to provide a unified approach to managing sign-in methods, improve security, and support modern authentication options such as Microsoft Authenticator, passkeys (FIDO2), and passwordless sign-in.
If an organization does not complete the migration or verify that its settings are configured correctly after the transition, users may experience issues when signing in, registering MFA methods, or resetting their passwords.
Once the migration has been completed, your Microsoft 365 environment will be: