← Previous day

Next day →
Day in brief

Custom CSS branding faces late-October retirement after July 21 new-use cutoff

Microsoft Entra’s most consequential change is the planned retirement of custom CSS layout and positioning properties in company branding by late October 2026. The schedule blocks new use from July 21, 2026, and affected branding will revert to default layouts after retirement. Other updates primarily refresh FIDO2 hardware references and clarify authentication terminology.

  • Microsoft Entra will retire custom CSS layout and positioning properties in company branding by late October 2026 to enhance security and reduce phishing risks. New use is blocked from July 21, 2026, and branding will revert to default layouts after retirement.

  • The FIDO2 hardware reference now reflects FIDO Metadata Service version 275, with updated model entries, AAGUIDs, capability indicators, and newly listed authenticators. Use the refreshed table to verify hardware eligibility and supported capabilities.

  • Compatibility indicators were updated for several Arculus, Feitian, Hyper FIDO, and IDmelon authenticators, while multiple vendor entries were removed. Use the revised compatibility table when evaluating or deploying FIDO2 authenticators.

  • The SAML protocol reference now labels synced passkeys as phishing-resistant MFA and clarifies that the certificate-based authentication designation applies to multi-factor CBA. The associated SAML mappings are unchanged.

  • The Optional Claims Reference now labels synced passkeys as PRMFA and specifies that the PRMFA certificate-based authentication entry applies to multi-factor CBA. The clearer labels help distinguish authentication methods when interpreting optional claims.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

10 updates

7

Microsoft Entra ID: Retirement of custom CSS layout and positioning properties in company branding

New

Microsoft Entra ID will retire custom CSS layout and positioning properties in company branding by late October 2026 to enhance security and reduce phishing risks. Organizations using these properties must update branding configurations before then; new use will be blocked from July 21, 2026. Branding will revert to default layouts after retirement.

Message CenterMC1458474 on mc.merill.net ↗Major updatePlan for change

Fido2 Hardware Vendor

Doc update

The security key entry’s table formatting was corrected by removing an extra space before a separator.

Fido2 Hardware Vendor

Doc update

The documentation now reflects FIDO Metadata Service version 275, with updated FIDO2 model entries, AAGUIDs, and capability indicators, including newly listed authenticators.

Fido2 Hardware Vendor

Doc update

The documentation updates compatibility indicators for several Arculus, Feitian, Hyper FIDO, and IDmelon authenticators and removes multiple vendor entries.

Fido2 Hardware Vendor

Doc update

The vendor table was re-rendered in its original order, with minor whitespace and line-formatting changes. Vendor names and support indicators are unchanged.

Fido2 Hardware Vendor

Doc update

Several FIDO2 hardware vendor entries were reordered to restore their previous sequence. Product names, identifiers, and support indicators remain unchanged.

1

Microsoft Entra ID: Passkey support for B2B users

New

Microsoft Entra ID will support passkey registration and sign-in for B2B users to meet resource tenant MFA requirements, enhancing phishing resistance. This feature, enabled by default, rolls out from October 2026 to February 2027, requiring no admin action but recommending policy reviews to align user scopes and MFA settings.

Message CenterMC1459133 on mc.merill.net ↗Stay informed
1

Optional Claims Reference

Doc update

The reference now explicitly labels synced passkeys as PRMFA and specifies that the PRMFA certificate-based authentication entry applies to multi-factor CBA.

1

Single Sign On Saml Protocol

Doc update

The documentation now labels synced passkeys as phishing-resistant MFA and clarifies that this designation for certificate-based authentication applies to multi-factor CBA. The associated SAML mappings are unchanged.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…