← Previous day

Next day →
Day in brief

Custom CSS branding guidance spells out July 21 cutoff and property retirement

Most of the day's entries were documentation maintenance, but several updates have direct planning or configuration implications. Entra ID branding guidance says tenants created after January 5, 2026, cannot use custom CSS, older tenants not already using it cannot configure it after July 21, 2026, and custom CSS layout and positioning properties are being retired. A new federated sign-in page documents cross-root-domain blocking and related Microsoft Graph beta APIs; provisioning, Token Protection, and Lifecycle Workflows also received substantive guidance.

  • Updated Entra ID branding guidance says tenants created after January 5, 2026, cannot use custom CSS. After July 21, 2026, older tenants that were not already using it cannot configure it; support for custom CSS layout and positioning properties is being retired.

  • A new Entra ID page explains that the policy blocks federated sign-ins when the trusted realm and mapped user account have different root domains. It also documents related Microsoft Graph beta APIs, which are subject to change and unsupported for production applications.

  • New Entra ID provisioning guidance documents clearing an existing target attribute when the source value is null or empty. The capability is opt-in, requires enabling “Flow null values” on both source and target mappings, and supports only single-valued attributes in specified inbound scenarios.

  • The Entra ID Token Protection reference now lists token protection for iOS/iPadOS and macOS as generally available. Supported web apps accessing Azure Resource Manager on macOS remain in preview.

  • ID Governance · Fundamentals
    Mover workflow access-removal timing

    ID Governance task guidance now applies “Remove all access package assignments for user” to both leaver and mover templates. For mover templates, scheduled removal defaults to 15 days; administrators can customize the timing or choose immediate removal.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

26 updates

7

Strengthen federated sign-in security

New feature

New documentation explains how the policy blocks federated sign-ins when the trusted realm and mapped user account have different root domains. It also documents the related Microsoft Graph beta APIs.

Customize Branding

RetirementAction required

The documentation now states that tenants created after January 5, 2026, cannot use custom CSS. After July 21, 2026, older tenants not already using it cannot configure it, and support for custom CSS layout and positioning properties is being retired.

Single Sign On Saml Protocol

Doc update

The documentation now identifies device-based X.509 authentication with the `x509` AMR value and explains that `x509` alone does not meet phishing-resistant MFA requirements. An additional authentication factor is required.

Optional Claims Reference

Doc update

The reference now distinguishes `hwk` for multifactor CBA from `x509` for single-factor CBA, adds device-based X.509 authentication, and explains that `x509` alone does not indicate phishing-resistant MFA.

Company Branding Css Template

RetirementAction required

The documentation now states that, after July 21, 2026, eligible tenants without existing custom CSS cannot configure it. It also expands the list of layout and positioning properties that will eventually be blocked and updates the inspection steps.

Deployment Guide Token Protection Apple

Doc update

The deployment guide no longer states that Platform SSO for macOS uses hardware-backed storage by default. The Intune setup link remains unchanged.

4

Licensing Service Plan Reference

Doc update

The reference was updated August 19, 2026, adding entries for several Dynamics 365 and Microsoft 365 plans and refreshing listed Microsoft 365 licensing rows.

Licensing Service Plan Reference

Doc update

The page’s last-updated date now reads October 29, 2025, and two Teams Calling Plan names use “country/region” instead of “country.” The downloadable CSV link is unchanged.

Licensing Service Plan Reference

Doc update

The page now states that its information was last updated on August 19, 2026; the CSV download link remains unchanged.

Licensing Service Plan Reference

Doc update

The document’s metadata date changed from July 1, 2026, to August 18, 2026. No product behavior or guidance changed.

4

Clear attribute values (Preview)

Private preview

New documentation explains how provisioning can clear an existing target attribute when its source value is null or empty. The capability is opt-in, requires enabling “Flow null values” on both source and target mappings, and supports only single-valued attributes in specified inbound scenarios.

Customize Application Attributes

Private preview

The documentation now states that null values are not sent by default. Clearing attribute values is available only in preview for API-driven inbound provisioning apps and isn’t supported for other provisioning scenarios.

Inbound Provisioning Api Faqs

Doc update

The FAQ now states that the /bulkUpload endpoint can clear existing user attributes and links to configuration guidance. It also clarifies that the endpoint cannot delete users and recommends Lifecycle Workflows for automated deletion after termination or disablement.

2

Tshoot Connect Sync Errors

Doc update

The troubleshooting guide now covers DataValidationFailed alongside IdentityDataValidationFailed, including cases where onPremisesObjectIdentifier changes during hard match operations. It also adds guidance for checking userPrincipalName formatting and using the documented hard match recovery paths.

Tshoot Connect Sync Errors

Doc update

The troubleshooting documentation now directs administrators to the Hard match scenarios and recovery paths when DataValidationFailed occurs during a hard match operation, while retaining guidance to validate userPrincipalName characters and format.

1

Token Protection Deployment Guide - Apple Platforms

Generally available

The guide removes the Preview designation, adds Microsoft Scout to the support matrix, and replaces detailed storage-flag instructions with updated Apple SSO plugin and Platform SSO guidance.

1

Token Protection

Generally available

The documentation now lists token protection for iOS/iPadOS and macOS as generally available. Supported web apps accessing Azure Resource Manager on macOS remain in preview.

1

Inbound Provisioning Api Concepts

New feature

The documentation now describes clearing mapped target attributes when inbound provisioning payloads contain null or empty values. It also recommends complete user records for full and delta sync when this preview capability is enabled.

4

Lifecycle Workflow Templates

Doc update

The mover workflow templates now list the “Remove all access package assignments for user” task, with removal scheduled by default for 15 days.

Lifecycle Workflows Deployment

Feature update

The task is now listed for both Leaver and Mover templates. The documentation also states that setting daysUntilExpiration schedules removal instead of removing assignments immediately.

Lifecycle Workflows Tasks Table

Doc update

The lifecycle workflows task table now lists “Remove all access package assignments for user” for both Leaver and Mover workflow templates.

1

Lifecycle Workflow Tasks

Feature update

The task now applies to both leaver and mover templates. For mover templates, scheduled removal defaults to 15 days; administrators can customize the timing or choose immediate removal.

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…