📋 Microsoft Entra Documentation Changes

Daily summary for changes since July 20th 2026, 8:12 PM PDT

Report generated on July 21st 2026, 8:12 PM PDT

📊 Summary

18
Total Commits
0
New Files
8
Modified Files
0
Deleted Files
8
Contributors

📝 Modified Documentation Files

+67 / -8 lines changed
Commit: Custom CSS positioning properties (#13826)
Changes:
Before
After
description: Reference guide for the CSS template selectors for customizing Microsoft Entra sign-in page company branding.
manager: pmwongera
ms.topic: reference
ms.date: 12/16/2025
ms.reviewer: almars
ms.custom: sfi-image-nochange
#Customer Intent: As an IT admin, I want to reference the CSS template for customizing company branding so that I can style my organization's sign-in pages.
---
 
Configuring your company branding for the user sign-in process provides a seamless experience in your applications that use Microsoft Entra ID as the identity and access management service. Use this CSS reference guide if you're using the [CSS template](https://download.microsoft.com/download/7/2/7/727f287a-125d-4368-a673-a785907ac5ab/custom-styles-template-013023.css) as part of the [customize company branding](reference-company-branding-css-template.md) process.
 
> [!IMPORTANT]
> Tenants created after January 5, 2026, will not have custom CSS available for company branding in Microsoft Entra ID tenants. Tenants created before January 5 can continue to use custom CSS.
>
> Microsoft Entra External ID tenants are not affected.
 
## HTML selectors
 
The following CSS styles become the default body and link styles for the whole page. Applying styles for other links or text override CSS selectors.
 
description: Reference guide for the CSS template selectors for customizing Microsoft Entra sign-in page company branding.
manager: pmwongera
ms.topic: reference
ms.date: 07/21/2026
ms.reviewer: almars
ms.custom: sfi-image-nochange, msecd-doc-authoring-1015
ai-usage: ai-assisted
#Customer Intent: As an IT admin, I want to reference the CSS template for customizing company branding so that I can style my organization's sign-in pages.
---
 
Configuring your company branding for the user sign-in process provides a seamless experience in your applications that use Microsoft Entra ID as the identity and access management service. Use this CSS reference guide if you're using the [CSS template](https://download.microsoft.com/download/7/2/7/727f287a-125d-4368-a673-a785907ac5ab/custom-styles-template-013023.css) as part of the [customize company branding](reference-company-branding-css-template.md) process.
 
> [!IMPORTANT]
> Tenants created after January 5, 2026 don't have custom CSS available for company branding in Microsoft Entra ID. Tenants created before January 5, 2026, can continue to use custom CSS.
>
> Microsoft Entra External ID tenants aren't affected.
 
## Deprecation of custom CSS positioning properties
 
As part of the [Microsoft Secure Future Initiative](https://www.microsoft.com/trust-center/security/secure-future-initiative), Microsoft Entra ID is retiring support for custom CSS *positioning properties* in company branding. These properties control where elements appear on the sign-in page and how they're layered, sized, and displayed. For example, they can move, overlap, resize, or hide page content. Retiring them keeps sign-in page layouts consistent and predictable across Microsoft Entra ID.
Modified by Chris Davis on Jul 21, 2026 8:54 PM
📖 View on learn.microsoft.com
+34 / -32 lines changed
Commit: Custom CSS positioning properties (#13826)
Changes:
Before
After
description: Instructions about how to add your organization's custom branding to the Microsoft Entra sign-in experience.
manager: pmwongera
ms.topic: how-to
ms.date: 12/16/2025
ms.reviewer: mkokkalera
ms.custom: sfi-image-nochange
# Customer intent: As a Microsoft Entra administrator, I want to customize the sign-in experience for my organization's users so that I can provide a consistent look and feel across all sign-ins.
---
 
 
:::image type="content" source="media/how-to-customize-branding/sign-in-page-map.png" alt-text="Screenshot of the sign-in page, with each of the company branding elements highlighted." lightbox="media/how-to-customize-branding/sign-in-page-map-expanded.png":::
 
1. **Favicon:** Small icon that appears on the left side of the browser tab.
1. **Header:** Space across the top of the sign-in page, behind the header logo.
1. **Header logo:** Logo that appears in the upper-left corner of the sign-in page.
1. **Background image:** The entire space behind the sign-in box.
1. **Page background color:** The entire space behind the sign-in box.
1. **Banner logo:** Logo that appears at the top of the sign-in box
1. **Sign-in page title:** Larger text that appears below the banner logo.
1. **Sign-in page description:** Text to describe the sign-in page.
description: Instructions about how to add your organization's custom branding to the Microsoft Entra sign-in experience.
manager: pmwongera
ms.topic: how-to
ms.date: 07/21/2026
ms.reviewer: mkokkalera
ms.custom: sfi-image-nochange, msecd-doc-authoring-1015
ai-usage: ai-assisted
# Customer intent: As a Microsoft Entra administrator, I want to customize the sign-in experience for my organization's users so that I can provide a consistent look and feel across all sign-ins.
---
 
 
:::image type="content" source="media/how-to-customize-branding/sign-in-page-map.png" alt-text="Screenshot of the sign-in page, with each of the company branding elements highlighted." lightbox="media/how-to-customize-branding/sign-in-page-map-expanded.png":::
 
1. **Favicon**: Small icon that appears on the left side of the browser tab.
1. **Header**: Space across the top of the sign-in page, behind the header logo.
1. **Header logo**: Logo that appears in the upper-left corner of the sign-in page.
1. **Background image**: The entire space behind the sign-in box.
1. **Page background color**: The entire space behind the sign-in box.
1. **Banner logo**: Logo that appears at the top of the sign-in box
1. **Sign-in page title**: Larger text that appears below the banner logo.
Modified by Alexander Pavlovsky on Jul 21, 2026 7:23 AM
📖 View on learn.microsoft.com
+9 / -53 lines changed
Commit: Revise tenant restrictions documentation for clarity (#13885)
Changes:
Before
After
- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.
- They help protect Microsoft Graph.
 
## Enforcement points for universal tenant restrictions
 
### Authentication plane (Microsoft Entra ID)
 
Authentication plane enforcement happens at the time of Microsoft Entra ID or Microsoft account authentication.
 
When the user is connected with the Global Secure Access client or via remote network connectivity, the tenant restrictions v2 policy is checked to determine if authentication should be allowed. If the user is signing in to the organization's tenant, the tenant restrictions v2 policy isn't applied. If the user is signing in to a different tenant, the policy is enforced.
 
Any application that's integrated with Microsoft Entra ID or that uses a Microsoft account for authentication supports universal tenant restrictions at the authentication plane.
 
### Data plane (Microsoft Graph)
 
Data plane enforcement is currently supported for Microsoft Graph. Data plane protection ensures that imported authentication artifacts can't be replayed from your organization's devices to exfiltrate data. An example of such an artifact is an access token that's obtained on another device and bypasses authentication plane enforcements defined in your tenant restrictions v2 policy.
 
## Prerequisites
 
 
- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.
- They help protect Microsoft Graph.
 
## Supported scenarios
 
### Microsoft Entra ID
 
Enforcement of tenant restrictions happens at the time of Microsoft Entra ID or Microsoft account authentication. When the user is connected with the Global Secure Access client or via remote network connectivity, the tenant restrictions v2 policy is checked to determine if authentication should be allowed. If the user is signing in to the organization's tenant, the tenant restrictions v2 policy isn't applied. If the user is signing in to a different tenant, the policy is enforced. This works for any application that uses the Entra ID (Work/School account) or Microsoft Account as its identity provider.
 
### Microsoft Graph
 
Tenant restrictions for Microsoft Graph ensures that tokens obtained on other devices can't be replayed from your organization's devices to exfiltrate data. If the malicious user signs in to their own tenant from their personal computer while connected to the public internet, extracts the access token for Microsoft Graph, and copies this token to their work device, tenant restrictions will block access with that token, since the token was not acquired from a trusted GSA network.
 
## Prerequisites
 
 
For more information about configuring these policies, see [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2).
 
## Enable Universal Tenant Restrictions
 
Modified by Chris Davis on Jul 21, 2026 8:54 PM
📖 View on learn.microsoft.com
+20 / -15 lines changed
Commit: Custom CSS positioning properties (#13826)
Changes:
Before
After
---
title: Customize the sign-in experience for your application with branding themes
description: Learn how to create branding themes and apply them to the sign-in experience for your application in Microsoft Entra ID.
ms.date: 04/27/2026
ms.reviewer:
ms.topic: how-to
#Customer intent: As a developer integrating with Microsoft Entra ID, I want to customize the sign-in experience for my application.
 
---
1. Browse to **Entra ID** > **Custom branding**.
 
1. On the **Company branding** page, select **Branding themes** and then select the **Themes** tab.
:::image type="content" source="./media/how-to-customize-branding-themes-apps/create-new-theme.png" alt-text="Screenshot of the Company Branding page and the Themes tab." lightbox="./media/how-to-customize-branding-themes-apps/create-new-theme.png":::
 
1. Select **Create new theme**.
1. On the **Basics** tab, enter a **Name** for your theme.
 
:::image type="content" source="./media/how-to-customize-branding-themes-apps/add-application-to-theme.png" alt-text="Screenshot of the Create a theme page and the Basics tab to apply themes to applications." lightbox="./media/how-to-customize-branding-themes-apps/add-application-to-theme.png":::
---
title: Customize the sign-in experience for your application with branding themes
description: Learn how to create branding themes and apply them to the sign-in experience for your application in Microsoft Entra ID.
ms.date: 07/21/2026
ms.reviewer:
ms.topic: how-to
ms.custom: msecd-doc-authoring-1015
ai-usage: ai-assisted
#Customer intent: As a developer integrating with Microsoft Entra ID, I want to customize the sign-in experience for my application.
 
---
1. Browse to **Entra ID** > **Custom branding**.
 
1. On the **Company branding** page, select **Branding themes** and then select the **Themes** tab.
 
:::image type="content" source="./media/how-to-customize-branding-themes-apps/create-new-theme.png" alt-text="Screenshot of the Company Branding page and the Themes tab." lightbox="./media/how-to-customize-branding-themes-apps/create-new-theme.png":::
 
1. Select **Create new theme**.
 
1. On the **Basics** tab, enter a **Name** for your theme.
+6 / -8 lines changed
Commit: Correct WCF source traffic types to Agent and Non-agent
Changes:
Before
After
 
Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:
 
- **Source traffic type filtering (preview)**: Scope rules to specific traffic types, such as agent, browser, or application.
- **HTTP method request filtering (preview)**: Block or allow specific HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.
 
> [!TIP]
 
## Configure source traffic type filtering (preview)
 
Source traffic type filtering lets you scope web content filtering rules to specific types of network traffic. You can enforce differentiated policies based on whether traffic originates from an AI agent, a web browser, or an application.
 
### Supported source traffic types
 
| Source type | Description |
| --- | --- |
| Agent | Traffic that originates from AI agents, such as Copilot agents or autonomous AI tools. |
| Browser | Traffic that originates from web browsers. |
| Application | Traffic that originates from desktop or mobile applications. |
| Unknown | Traffic where the source type can't be determined. |
 
Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:
 
- **Source traffic type filtering (preview)**: Scope rules to specific traffic types, either agent or non-agent.
- **HTTP method request filtering (preview)**: Block or allow specific HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.
 
> [!TIP]
 
## Configure source traffic type filtering (preview)
 
Source traffic type filtering lets you scope web content filtering rules to specific types of network traffic. You can enforce differentiated policies based on whether traffic originates from an AI agent or a non-agent source.
 
### Supported source traffic types
 
| Source type | Description |
| --- | --- |
| Agent | Traffic that originates from AI agents, such as Copilot agents or autonomous AI tools. |
| Non-agent | Traffic that originates from any source other than an AI agent, such as web browsers and applications. |
 
### Configure the source traffic type condition
Modified by Mark Wahl on Jul 21, 2026 5:21 PM
📖 View on learn.microsoft.com
+7 / -7 lines changed
Commit: update user sponsor section
Changes:
Before
After
 
### Agent identity sponsors vs. agent's user account sponsors
 
In Microsoft Agent ID, agents can have an [agent's user account](agent-users.md) created in order to access user-oriented services. The user account and the agent's identity, blueprint, and blueprint principal may all have sponsors associated with them. There are differences between the user account sponsors and sponsors of the agent identity, blueprint, or blueprint principal.
 
Agent user account sponsors are the same as normal [user sponsors](../external-id/b2b-sponsors.md). They are not authorized to make any changes to their sponsored users, but they can request access on the user's behalf and may be involved in approval flows. In contrast, sponsors of agent identities, blueprints, and blueprint principals have limited access to manage those identities directly and can also request access or give approvals in lifecycle workflows.
 
| | Agent user account sponsors | Agent identity, blueprint, blueprint principal sponsors |
|--|--|--|
| **Allowed types** | Users (including guests), groups (any) | Users (including guests), select groups (dynamic membership, Microsoft 365). Role-assignable groups not supported. |
| **Limits** | Maximum 5 sponsors | Maximum 100 sponsors, with no more than 5 groups |
| **Authorization** | No direct authorization to modify sponsors users | Delete or disable the agent identity and modify its sponsors |
| **Required** | Not required | Required on create for agent identities and agent blueprints |
 
When an agent is represented by both an agent identity object and an agent user account, we recommend maintaining the agent identity sponsor as the primary user or group responsible for the agent.
 
Different scenarios may require different types of access or authorization for an agent identity and its associated user account. Sponsors for each object can [request access packages](../id-governance/entitlement-management-request-access.md) on behalf of the identity they sponsor. In most cases, the same user or group should be set as the sponsor on both objects to ensure they can request the appropriate access for both the agent identity and the agent's user account as needed.
 
## Managers
 
 
### Agent identity sponsors vs. agent's user account sponsors
 
In Microsoft Agent ID, the agent's identity, blueprint, and blueprint principal may all have sponsors associated with them. In addition, agents can have an [agent's user account](agent-users.md) created in order to access user-oriented services. While the Entra user has a sponsor relationship, there are differences between the user account sponsors and sponsors of the agent identity, blueprint, or blueprint principal.
 
The sponsor relationship on a user is primarily intended for the [sponsors of B2B guests](../external-id/b2b-sponsors.md). They are not authorized to make any changes to their sponsored users, but they can request access on the user's behalf and may be involved in approval flows. In contrast, sponsors of agent identities, blueprints, and blueprint principals have limited access to manage those identities directly and can also request access or give approvals in lifecycle workflows.
 
When an agent is represented by both an agent identity object and an agent user account, we recommend maintaining the agent identity sponsor as the primary user or group responsible for the agent.
 
If you require different access or authorization for an associated user account than from its agent identity, then sponsors for each object can [request access packages](../id-governance/entitlement-management-request-access.md) on behalf of the identity they sponsor. If you need to set a sponsor on an agent's user account, then the same user or group should be set as the sponsor on both objects to ensure they can request the appropriate access for both the agent identity and the agent's user account as needed.
 
| | Agent user account sponsors | Agent identity, blueprint, blueprint principal sponsors |
|--|--|--|
| **Allowed types** | Users (including guests), groups (any) | Users (including guests), select groups (dynamic membership, Microsoft 365). Role-assignable groups not supported. |
| **Limits** | Maximum 5 sponsors | Maximum 100 sponsors, with no more than 5 groups |
| **Authorization** | No direct authorization to modify sponsored users | Delete or disable the agent identity and modify its sponsors |
| **Required** | Not required | Required on create for agent identities and agent blueprints |
 
## Managers
 
Modified by marinasanchezz1 on Jul 21, 2026 8:34 PM
📖 View on learn.microsoft.com
+6 / -0 lines changed
Commit: Add FAQ: external MFA methods and SMS/voice retirement scope
Changes:
Before
After
 
Passkey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.
 
### What if I have different plans for my tenant than enabling passkeys for SMS/voice users (such as configuring a customer configured telecom provider or migrating users to another authentication method)?
 
A temporary opt-out will be available for the September 1, 2026 through February 1, 2027 changes. This allows you to delay passkey and Registration Campaign enablement while you complete transition activities, such as configuring customer-managed telecom providers or migrating to other authentication methods. API support and information for opting out will be available starting August 1, 2026.
 
 
 
 
 
 
 
Passkey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.
 
### Are external MFA methods impacted by SMS and voice retirement?
 
No, only SMS and voice authentication method policies and legacy MFA policies are retired.
 
On September 1, 2026, users that are enabled for SMS or voice in the authentication method policies or legacy MFA policies are auto-enabled for passkeys and nudged to register. External MFA users aren't in scope unless they're also enabled for SMS or voice.
 
### What if I have different plans for my tenant than enabling passkeys for SMS/voice users (such as configuring a customer configured telecom provider or migrating users to another authentication method)?
 
A temporary opt-out will be available for the September 1, 2026 through February 1, 2027 changes. This allows you to delay passkey and Registration Campaign enablement while you complete transition activities, such as configuring customer-managed telecom providers or migrating to other authentication methods. API support and information for opting out will be available starting August 1, 2026.
Modified by Alexander Pavlovsky on Jul 21, 2026 7:23 AM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: Revise tenant restrictions documentation for clarity (#13885)
Changes:
Before
After
 
1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).
 
1. [Enable Global Secure Access signaling for tenant restrictions](../global-secure-access/how-to-universal-tenant-restrictions.md#enable-global-secure-access-signaling-for-tenant-restrictions).
 
1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.
 
1. [Validate Universal Tenant Restrictions](../global-secure-access/how-to-universal-tenant-restrictions.md#validate-the-authentication-plane-protection).
 
## Troubleshoot
 
 
1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).
 
1. [Enable Universal Tenant Restrictions](../global-secure-access/how-to-universal-tenant-restrictions.md#enable-universal-tenant-restrictions).
 
1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.
 
1. [Validate Universal Tenant Restrictions enforcement](../global-secure-access/how-to-universal-tenant-restrictions.md#validate-tenant-restrictions-enforcement).
 
## Troubleshoot