Week in brief

Custom branding CSS retirement sets October deadline for Entra administrators

The clearest operational deadline is Microsoft Entra’s retirement of custom CSS layout and positioning properties in company branding: new use is blocked from July 21, 2026, and existing branding will revert to default layouts after retirement in late October. Two authentication changes are scheduled for October: B2B users will gain passkey registration and sign-in support, while Windows Hello for Business and macOS Platform SSO will count as standalone MFA factors. The period also added actionable preview guidance for clearing null or empty values through inbound provisioning and for securing GitHub flexible federated identity credentials with immutable repository claims.

  • Microsoft says new use is blocked from July 21, 2026. Retirement is planned for late October 2026, after which branding reverts to default layouts. Organizations using these properties must update their branding configurations before the deadline.

  • Passkey registration and sign-in for B2B users will be enabled by default and roll out from October 2026 through February 2027, helping guests meet resource-tenant MFA requirements. No administrator action is required, although Microsoft recommends reviewing user scopes and MFA policies.

  • Starting in October 2026, Microsoft Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors, allowing users to satisfy MFA requirements without an additional passkey. No configuration change is needed; onboarding and MFA registration guidance should be updated.

  • When a source value is null or empty, provisioning can clear the existing target attribute. Administrators must enable “Flow null values” on both the source and target mappings; the behavior supports only single-valued attributes in specified inbound provisioning scenarios.

  • Updated preview guidance requires a GitHub credential to match `sub` plus `repository_id`, `repository_owner_id`, or both. Portal and Microsoft Graph examples now include these claims; administrators configuring trust should use the numeric immutable values from the GitHub OIDC token.

For Entra administrators

Audit company-branding CSS configurations and replace affected layout or positioning properties before the late-October retirement. No configuration change is required for B2B passkeys or standalone MFA recognition, but review MFA policy scopes and update onboarding guidance. For provisioning, enable Flow null values on both source and target mappings only where empty values should clear target data; for GitHub federation, update flexible credentials to include the required immutable repository claims.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

14

Microsoft Entra ID: Retirement of custom CSS layout and positioning properties in company branding

New

Microsoft Entra ID will retire custom CSS layout and positioning properties in company branding by late October 2026 to enhance security and reduce phishing risks. Organizations using these properties must update branding configurations before then; new use will be blocked from July 21, 2026. Branding will revert to default layouts after retirement.

21 August 2026
Message CenterMC1458474 on mc.merill.net ↗Major updatePlan for change

Fido2 Hardware Vendor

Doc update

The security key entry’s table formatting was corrected by removing an extra space before a separator.

21 August 2026

Fido2 Hardware Vendor

Doc update

The documentation now reflects FIDO Metadata Service version 275, with updated FIDO2 model entries, AAGUIDs, and capability indicators, including newly listed authenticators.

21 August 2026

Fido2 Hardware Vendor

Doc update

The documentation updates compatibility indicators for several Arculus, Feitian, Hyper FIDO, and IDmelon authenticators and removes multiple vendor entries.

21 August 2026

Fido2 Hardware Vendor

Doc update

The vendor table was re-rendered in its original order, with minor whitespace and line-formatting changes. Vendor names and support indicators are unchanged.

21 August 2026

Fido2 Hardware Vendor

Doc update

Several FIDO2 hardware vendor entries were reordered to restore their previous sequence. Product names, identifiers, and support indicators remain unchanged.

21 August 2026

Strengthen federated sign-in security

New feature

New documentation explains how the policy blocks federated sign-ins when the trusted realm and mapped user account have different root domains. It also documents the related Microsoft Graph beta APIs.

20 August 2026

Customize Branding

RetirementAction required

The documentation now states that tenants created after January 5, 2026, cannot use custom CSS. After July 21, 2026, older tenants not already using it cannot configure it, and support for custom CSS layout and positioning properties is being retired.

20 August 2026

Single Sign On Saml Protocol

Doc update

The documentation now identifies device-based X.509 authentication with the `x509` AMR value and explains that `x509` alone does not meet phishing-resistant MFA requirements. An additional authentication factor is required.

20 August 2026

Optional Claims Reference

Doc update

The reference now distinguishes `hwk` for multifactor CBA from `x509` for single-factor CBA, adds device-based X.509 authentication, and explains that `x509` alone does not indicate phishing-resistant MFA.

20 August 2026

Company Branding Css Template

RetirementAction required

The documentation now states that, after July 21, 2026, eligible tenants without existing custom CSS cannot configure it. It also expands the list of layout and positioning properties that will eventually be blocked and updates the inspection steps.

20 August 2026

Deployment Guide Token Protection Apple

Doc update

The deployment guide no longer states that Platform SSO for macOS uses hardware-backed storage by default. The Intune setup link remains unchanged.

20 August 2026
7

Secure add-on tenant creation

Doc update

The page title no longer includes “(preview),” and the prerelease product notice was removed.

22 August 2026

Quickstart - Access and create new tenant

Feature update

The documentation now lists a paid Azure subscription associated with an Enterprise Agreement or pay-as-you-go billing account, replacing the previous MCA subscription requirement.

22 August 2026

Create New Tenant

Doc update

The Governed Workforce tenant creation guidance now links the Microsoft Online Subscription Agreement and related billing agreement references.

22 August 2026

Create New Tenant

Doc update

The documentation now describes the requirement as an Enterprise Agreement (EA) or Pay-As-You-Go subscription and references MOSA and MCA billing agreements.

22 August 2026

Create New Tenant

Doc update

The documentation refreshes troubleshooting guidance for creating Governed Workforce tenants, including paid Azure subscription and billing-account requirements.

22 August 2026

Token Protection

Generally available

The documentation now lists token protection for iOS/iPadOS and macOS as generally available. Supported web apps accessing Azure Resource Manager on macOS remain in preview.

20 August 2026

Assign App Owners

Doc update

The documentation now compares application owners with application administrators, stating that owners can manage only the enterprise applications they own and have equivalent permissions within that application scope.

19 August 2026
6

Optional Claims Reference

Doc update

The reference now explicitly labels synced passkeys as PRMFA and specifies that the PRMFA certificate-based authentication entry applies to multi-factor CBA.

21 August 2026

Licensing Service Plan Reference

Doc update

The reference was updated August 19, 2026, adding entries for several Dynamics 365 and Microsoft 365 plans and refreshing listed Microsoft 365 licensing rows.

20 August 2026

Licensing Service Plan Reference

Doc update

The page’s last-updated date now reads October 29, 2025, and two Teams Calling Plan names use “country/region” instead of “country.” The downloadable CSV link is unchanged.

20 August 2026

Licensing Service Plan Reference

Doc update

The page now states that its information was last updated on August 19, 2026; the CSV download link remains unchanged.

20 August 2026

Licensing Service Plan Reference

Doc update

The document’s metadata date changed from July 1, 2026, to August 18, 2026. No product behavior or guidance changed.

20 August 2026

Licensing Service Plan Reference

Doc update

The reference was updated August 14, 2026, adding Windows 10 ESU service-plan identifiers to two Windows 365 plan entries.

18 August 2026
6

Clear attribute values (Preview)

Private preview

New documentation explains how provisioning can clear an existing target attribute when its source value is null or empty. The capability is opt-in, requires enabling “Flow null values” on both source and target mappings, and supports only single-valued attributes in specified inbound scenarios.

20 August 2026

Customize Application Attributes

Private preview

The documentation now states that null values are not sent by default. Clearing attribute values is available only in preview for API-driven inbound provisioning apps and isn’t supported for other provisioning scenarios.

20 August 2026

Inbound Provisioning Api Faqs

Doc update

The FAQ now states that the /bulkUpload endpoint can clear existing user attributes and links to configuration guidance. It also clarifies that the endpoint cannot delete users and recommends Lifecycle Workflows for automated deletion after termination or disablement.

20 August 2026

Synchronization

Public preview

The synchronization documentation now describes enhanced support for synchronizing sAMAccountName with Microsoft Entra Domain Services and links to dedicated guidance.

18 August 2026
3

Microsoft Entra ID: Passkey support for B2B users

New

Microsoft Entra ID will support passkey registration and sign-in for B2B users to meet resource tenant MFA requirements, enhancing phishing resistance. This feature, enabled by default, rolls out from October 2026 to February 2027, requiring no admin action but recommending policy reviews to align user scopes and MFA settings.

21 August 2026
Message CenterMC1459133 on mc.merill.net ↗Stay informed

Token Protection Deployment Guide - Apple Platforms

Generally available

The guide removes the Preview designation, adds Microsoft Scout to the support matrix, and replaces detailed storage-flag instructions with updated Apple SSO plugin and Platform SSO guidance.

20 August 2026
2

Single Sign On Saml Protocol

Doc update

The documentation now labels synced passkeys as phishing-resistant MFA and clarifies that this designation for certificate-based authentication applies to multi-factor CBA. The associated SAML mappings are unchanged.

21 August 2026

Inbound Provisioning Api Concepts

New feature

The documentation now describes clearing mapped target attributes when inbound provisioning payloads contain null or empty values. It also recommends complete user records for full and delta sync when this preview capability is enabled.

20 August 2026
2

Tshoot Connect Sync Errors

Doc update

The troubleshooting guide now covers DataValidationFailed alongside IdentityDataValidationFailed, including cases where onPremisesObjectIdentifier changes during hard match operations. It also adds guidance for checking userPrincipalName formatting and using the documented hard match recovery paths.

20 August 2026

Tshoot Connect Sync Errors

Doc update

The troubleshooting documentation now directs administrators to the Hard match scenarios and recovery paths when DataValidationFailed occurs during a hard match operation, while retaining guidance to validate userPrincipalName characters and format.

20 August 2026
20

Deploy Microsoft Entra Tenant Governance end to end

Feature update

The deployment guide now documents a paid Azure subscription linked to an Enterprise Agreement or pay-as-you-go billing account, with Tenant Contributor or Subscription Owner/Creator access for the selected subscription.

22 August 2026

Create Lifecycle Workflow

New feature

The documentation now describes creating a lifecycle workflow by cloning an existing workflow in the Microsoft Entra admin center, including review and customization steps.

22 August 2026

Create a governed workforce tenant

Feature update

The documentation now specifies paid-account, billing, tenant-creation permission, role, and default governance-policy requirements for creating governed workforce tenants. Free or trial tenants cannot create additional tenants, and EA or pay-as-you-go billing accounts are supported.

22 August 2026

Automatic formation of governance relationships

Feature updateAction required

The documentation now specifies that secure add-on tenant creation requires an existing paid Azure subscription and resource group, with the subscription associated with an Enterprise Agreement.

22 August 2026

Automatic formation of governance relationships

Feature update

The documentation now specifies selecting an existing Microsoft Customer Agreement (MCA) subscription and resource group from the billing account when creating a tenant with the secure add-on tenant creation feature.

22 August 2026

Create Tenant

Doc update

The tenant creation guidance now links references to the Microsoft Entra ID Free billing asset to the relevant billing documentation instead of the previous signals-and-metrics page.

22 August 2026

Create Tenant

Feature update

The documentation now labels the governing tenant’s default governance policy template as optional instead of a required prerequisite. The tenant creation service still uses only the default template (ID: `default`).

22 August 2026

Create Tenant

Feature update

The prerequisite now specifies that the home tenant must have at least one paid, license-based Microsoft product. Free and trial licenses do not qualify.

22 August 2026

Automatic Governance Relationships

Doc update

The secure add-on tenant creation documentation now refers to selecting an existing subscription, rather than specifically an existing Microsoft Customer Agreement subscription, from the billing account.

22 August 2026

Create Tenant

Doc update

The documentation now says the home tenant—not the governing tenant—must have the default governance policy template for this optional prerequisite. The service uses the template with ID `default`.

22 August 2026

Create Tenant

Doc update

The documentation now explicitly states that the required Enterprise Agreement or Pay-As-You-Go subscription must be paid.

22 August 2026

Create Tenant

Doc update

The document’s `ms.author` metadata changed from `tafra00` to `tazkiaafra`.

22 August 2026

Create Tenant

Doc update

The guide now links the Microsoft Online Subscription Agreement (MOSA) in its billing-account prerequisites. The Enterprise Agreement and Pay-As-You-Go references remain.

22 August 2026

Create Tenant

Doc update

The prerequisite now refers to Enterprise Agreement or Pay-As-You-Go subscriptions and identifies MOSA and MCA subscriptions, replacing billing-account wording.

22 August 2026

Create Tenant

Doc update

The tenant creation guide now explicitly states that the required subscription permissions are Azure Resource Manager (ARM) permissions, provided through the Tenant Contributor or Subscription Owner/Creator role.

22 August 2026

Lifecycle Workflow Templates

Doc update

The mover workflow templates now list the “Remove all access package assignments for user” task, with removal scheduled by default for 15 days.

20 August 2026

Lifecycle Workflows Deployment

Feature update

The task is now listed for both Leaver and Mover templates. The documentation also states that setting daysUntilExpiration schedules removal instead of removing assignments immediately.

20 August 2026

Lifecycle Workflows Tasks Table

Doc update

The lifecycle workflows task table now lists “Remove all access package assignments for user” for both Leaver and Mover workflow templates.

20 August 2026
4

Deployment Guide

Doc update

The secure tenant creation guidance now links the Microsoft Online Subscription Agreement (MOSA) reference alongside the existing Enterprise Agreement and Pay-As-You-Go links.

22 August 2026

Deployment Guide

Doc update

The deployment guide now refers to either a paid Enterprise Agreement or Pay-As-You-Go subscription and adds Microsoft Online Subscription Agreement terminology.

22 August 2026

Deployment Guide

Doc update

The secure tenant creation prerequisites were updated to clarify the required Azure Resource Manager permissions.

22 August 2026

Lifecycle Workflow Tasks

Feature update

The task now applies to both leaver and mover templates. For mover templates, scheduled removal defaults to 15 days; administrators can customize the timing or choose immediate removal.

20 August 2026
2

Sign In With Passkey

New feature

The documentation now describes using the preview credential management API with delegated permissions so signed-in customers can list, register, and delete their own passkeys. It also clarifies that the sample uses high-privilege administrator provisioning and is for testing.

22 August 2026
1
1

Web filtering in Global Secure Access (V2)

Doc update

The documentation now explains that V2 selects the first applicable profile containing a V2 policy, does not support user or group targeting on individual rules, and may produce different enforcement from V1 during migration.

19 August 2026
2

Set up a Flexible Federated identity credential (preview)

Feature updateAction required

The guidance now requires GitHub flexible federated identity credentials to match `sub` plus `repository_id`, `repository_owner_id`, or both. Portal and Microsoft Graph examples include these claims and optional workflow matching.

18 August 2026

Flexible federated identity credentials (preview)

Feature update

The documentation now states that GitHub flexible federated identity credentials must match `sub` and at least one immutable claim: `repository_id` or `repository_owner_id`. It also updates examples and operator support details.

18 August 2026
1
8

Global Secure Access Client for macOS Release Notes

Feature updateAction required

The release notes now document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes.

22 August 2026

Install the Global Secure Access Client for macOS

Doc update

The page no longer includes the note about `com.microsoft.autoupdate2` or the optional instruction to remove it from Intune detection rules. The metadata date and custom tag were also reverted.

22 August 2026

Install Macos Client

Doc update

The macOS client installation guidance now states that removing `com.microsoft.autoupdate2` from Intune detection rules is optional.

22 August 2026

Install Macos Client

Doc update

The documentation now warns that, starting with version 1.1.26060207, including the already-installed com.microsoft.autoupdate2 application in Intune detection rules might cause a conflict.

22 August 2026

Install Macos Client

Doc update

The macOS client installation guidance now clarifies that, starting with version 1.1.26060207, administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules.

22 August 2026

Macos Client Release History

Doc update

The macOS client release history now says administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules; the app package includes this application.

22 August 2026
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…