Have you ever stopped to think about how many times a day you log in to different services? Every login is a potential attack surface, and that is why multi-factor authentication, or MFA (Multi-Factor Authentication), is the cornerstone of corporate cybersecurity.
The deadline announced by Microsoft for the removal of legacy, basic MFA and SSPR (Self-Service Password Reset) policy management was September 30, 2025. This change has already taken place or is currently being implemented automatically for organizations that did not perform the migration themselves. This is not just a technical update, but a strategic move toward a significantly more modern and secure digital environment.
What does the change mean in practice now?
The change primarily affects IT management, but over time it will guide the entire organization toward more secure authentication methods.
The old Legacy MFA model, where settings were managed in a decentralized, per-user manner, has now been retired as a management tool. It was difficult to scale and audit. Additionally, the old model often supported insecure methods, such as text messages (SMS) and phone calls, which are vulnerable to phishing.
Now, all authentication method management has been moved to a single, centralized location: the new Authentication Methods Policy. This new model is located in the Microsoft Entra ID (formerly Azure AD) admin center. It enables centralized management—all settings are in one place, which simplifies maintenance.
The new model introduces new, more secure options, such as Microsoft Authenticator number matching (number matching), FIDO2 security keys, and passwordless login. At the same time, MFA and SSPR are now combined into the same management model. However, it is worth noting that the increased flexibility achieved with the new model (e.g., more granular control through Conditional Access policies) is directly tied to the Microsoft 365 license levels in use.
What does the change mean for the end user and the administrator?
For the end user, the change means that the transition to more secure authentication methods has now accelerated. While older methods may still work in automatically migrated environments, recommended and more secure methods, such as Authenticator app number matching or FIDO2 keys, are becoming more common. In the long run, this improves protection for every user, as their data becomes even more secure.
For the administrator, the change is more significant. Managing old, decentralized settings is now a thing of the past. Instead, all authentication methods are managed from one centralized location through the new Authentication Methods Policy. This simplifies management and makes it more efficient. The administrator can now manage all authentication methods at once and define security policies by group or through Conditional Access policies. This allows for more flexible and detailed security policies, saving time and reducing the risk of human error.
Why is now the time to ensure a successful transition?
Although Microsoft has already handled the transition to the new management model automatically for some organizations, this does not guarantee that the organization has moved to using the most secure MFA methods. In many cases, the automatic migration has simply moved old, weaker settings into the new management model. Therefore, it is critically important to switch to using the most secure MFA methods.
Benefits of the change (implementable now):
- Improved security: Removing insecure methods (such as SMS) and switching to number matching effectively prevents “MFA spam” attacks, for example.
- Simplified management: A centralized policy reduces the IT administrative burden and makes security management clearer.
- Better user experience: Modern and secure methods, such as FIDO2 keys, provide a faster and more seamless login experience.
How does Getafix help you now?
Even though the deadline announced by Microsoft has passed and the transition to the new management model has taken place, there is a significant pitfall here. As Getafix’s IT experts point out, the automatic migration has only moved old settings under a new umbrella. “The change itself does not solve the security problem if the organization continues to use weak authentication methods like text messages,” they summarize. Therefore, it is critically important to switch to using the most secure MFA methods.
Now is the time to audit and optimize the situation. At Getafix, we are here to ensure that the transition is managed, secure, and that you are utilizing the full potential of the new model.
Our action plan for post-migration optimization is clear and effective:
- Audit: We evaluate how Microsoft has handled the automatic transition and which insecure authentication methods you still have enabled.
- Finalizing the transition: We plan the measures to disable insecure methods (e.g., SMS) and force users to switch to more secure methods.
- Implementation: Our experts implement the changes to the new, centralized Authentication Methods Policy, ensuring that settings are configured according to best practices.
- Training: We help train your staff on how to use the new, more secure authentication methods, so that security improves without compromising the user experience.
Contact our experts today, and let’s work together to ensure your company is truly secure in accordance with Microsoft’s new requirements.
Abbreviations and Professional Terminology in Plain Language
MFA (Multi-Factor Authentication): Multi-factor authentication. This means that the user must prove their identity in at least two different ways (e.g., with a password and a code sent via a phone app), which makes stealing credentials significantly more difficult.
SSPR (Self-Service Password Reset): Self-service password reset. A system that allows users to change or reset a forgotten password themselves without having to contact IT support.
Microsoft Entra ID: Microsoft’s identity management service. Formerly known as Azure AD. It is the foundation that manages your company’s user accounts and access to all Microsoft 365 and cloud services.
Legacy MFA: The old MFA management model. Refers to Microsoft’s old, decentralized way of managing MFA settings, which has now been replaced by a new, centralized model. It often supported less secure verification methods, such as SMS.
Authentication Methods Policy: The new, centralized authentication methods policy. The new location in Microsoft Entra ID where all user authentication settings (both MFA and SSPR) are managed uniformly.
Conditional Access: Access control using rules. This tool allows IT management to define when and how users have access to services. For example: “Require MFA verification if the user attempts to log in from an unknown country or device.”
FIDO2 Security Key: A physical key for passwordless login. A highly secure device (e.g., a USB stick) used for passwordless login. It is resistant to phishing.