Microsoft Entra ID will retire support for custom CSS positioning properties in company branding starting October 2026 to enhance security and phishing resistance. Existing users must remove these properties by then, as no migration path exists. Branding elements remain visible but may revert to default placement.
Workload ID credential guidance is more prescriptive; SMS/voice retirement scope is limited to public cloud
The period contained three documentation updates and no supplied evidence of a new feature launch, preview, or general-availability change. The meaningful changes clarify Workload ID federated-credential values and GitHub subject mapping, while an Entra ID retirement page now distinguishes public-cloud timing from other cloud environments.
- GitHub Workload ID guidance specifies app object IDs and per-subject credentials
Workload ID · Microsoft identity platform
The updated GitHub immutable-subjects guidance says to replace `<application-object-id>` with the object ID of the app registration and create one credential for each subject presented by the workflow, such as a branch or environment. This is configuration guidance, not evidence of a new capability or changed service behavior.
- Federated-credential documentation shows the token-exchange audience value
Workload ID · Security
The mutable-subjects documentation update includes `"audiences": ["api://AzureADTokenExchange"]`. The supplied evidence establishes a documentation change only, so administrators should use the value to verify applicable federated-credential definitions rather than treat it as proof of a tenant-wide behavior change.
- SMS and voice retirement guidance is explicitly scoped to public cloud
Entra ID · Authentication
The Entra ID retirement documentation now states that its timeline applies to public cloud environments only. Other cloud environments will follow on a later schedule, with advance communications promised; no specific dates or migration actions are included in this update.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
5 updates
Microsoft Entra ID
3 updatesSms Voice Retirement
UpdatedThis timeline applies to public cloud environments only. Other cloud environments will follow on a later schedule, and we will provide advance communications to help customers prepare for the transition.
Starting June 15, 2026, Conditional Access policies targeting All resources with exclusions will be enforced for sign-ins requesting only certain OIDC or directory scopes. Some users may face new challenges like MFA. Most organizations need no action, but custom apps requesting only these scopes should be evaluated.
Microsoft Entra Workload ID
2 updatesReplace `<application-object-id>` with the object ID of your app registration. Create one credential for each subject the workflow presents, such as a different branch or environment.
"audiences": ["api://AzureADTokenExchange"]
