Entra ID

Microsoft Entra ID Branded Sign-In CSS Changes 2026

2 min read

Summary

Microsoft Entra ID is tightening the security of branded sign-in pages by retiring support for custom CSS positioning properties starting October 26, 2026. Organizations that use these properties in company branding should review and remove them now to avoid layout changes and maintain a trusted sign-in experience.

Need help with Entra ID?Talk to an Expert

Microsoft Entra ID branded sign-in security changes

Introduction

Microsoft is updating Microsoft Entra ID custom branding to make branded sign-in pages more secure, consistent, and resistant to phishing. For IT teams that rely on customized sign-in experiences, this change matters because unsupported CSS positioning properties will stop working in 2026, with broader custom CSS retirement planned for 2027.

What’s changing

Microsoft announced a phased retirement of custom CSS used in Entra ID branded sign-ins:

  • July 21, 2026: Tenants not already using custom CSS positioning properties can no longer configure them.
  • October 26, 2026: Custom CSS positioning properties will be retired globally.
  • Later in 2027: Microsoft plans to retire all custom CSS, with advance notice and alternative customization options.

The change is designed to reduce the risk of deceptive sign-in page layouts and improve trusted, recognizable authentication experiences.

Affected CSS properties

Organizations should review branding configurations for these deprecated properties:

  • position
  • top, right, bottom, left, z-index
  • margin, margin-top, margin-bottom, margin-left, margin-right
  • transform
  • opacity
  • overflow
  • filter
  • pointer-events
  • clip-path
  • mix-blend-mode
  • translate

After October 26, 2026, these properties will be blocked and no longer function.

Impact on administrators

If your tenant currently uses these CSS properties in Company Branding or Branding Themes, your sign-in page layout may change once the properties are retired. In most cases, logos, text, and images will still appear, but they will fall back to default placement.

Not all tenants are affected:

  • Affected: Existing Entra ID tenants already using the deprecated positioning properties
  • Not affected: Tenants not using those properties, new tenants created after January 5, 2026, and Microsoft Entra External ID tenants

What admins should do now

Microsoft recommends reviewing your branding configuration as soon as possible.

  1. Sign in with a Global Administrator or Branding Administrator role.
  2. Use Microsoft Graph Explorer to query your organization and branding localizations.
  3. Export or copy the branding localization JSON.
  4. Run the JSON through Microsoft’s provided detection tool to identify impacted locales and properties.
  5. Remove deprecated CSS properties before October 26, 2026.

Next steps

Admins should test branded sign-in pages early and remove unsupported CSS before enforcement begins. This will help avoid unexpected layout issues and support Microsoft’s broader move toward more secure, phishing-resistant authentication experiences.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Entra IDcustom brandingsign-in securityphishing resistanceMicrosoft Graph

Related Posts

Entra ID

Microsoft Entra Passkeys for External IdP App Sign-Ins

Microsoft has made browser-based authentication for external identity providers generally available for supported Microsoft app sign-ins on Android, iOS, and managed macOS. This lets federated Microsoft 365 users use passkeys, FIDO2 security keys, and eligible SSO sessions in apps like Outlook, Teams, and OneDrive, reducing password fallback and embedded web view limitations.

Entra ID

Microsoft Entra Tenant Governance Webinars 2026

Microsoft is promoting upcoming webinars focused on securing multi-tenant environments with Microsoft Entra Tenant Governance, now generally available. The sessions highlight how organizations can detect shadow tenants, apply consistent governance, and build a stronger identity foundation for AI readiness.

Entra ID

Microsoft Entra App Gallery Self-Service Onboarding Preview

Microsoft has launched a public preview of self-service onboarding for new Microsoft Entra App Gallery applications. The new workflow lets publishers validate OIDC, SAML, and provisioning integrations before submission, then create, submit, and track app listings in the Entra admin center, reducing delays and rework.

Entra ID

Microsoft Entra Private Access Replaces VPNs

Microsoft is positioning Entra Private Access as a practical replacement for traditional VPNs, using identity-driven, per-app access instead of broad network tunnels. The guidance outlines a phased migration approach that helps IT teams reduce attack surface, strengthen Zero Trust controls, and simplify remote access operations.

Entra ID

HiBob Microsoft Entra Integration Now Generally Available

Microsoft has announced general availability of HiBob’s native integration with Microsoft Entra, enabling HR-driven identity lifecycle automation for joiners, movers, and leavers. The integration helps IT teams govern provisioning and access changes across hybrid and cloud environments while reducing manual processes and security risk.

Entra ID

Microsoft Entra September 2026: Key Identity Updates

Microsoft Entra's September 2026 updates introduce new tenant governance, user-centric access reviews, lifecycle workflow cloning, and passwordless resource accounts for Teams devices. The release also adds cloud-to-AD provisioning, AI-focused MCP Firewall protections, and important deadlines for MemberOf-based configurations and permission scope changes.