Organizations are increasingly modernizing identity, access, and device management by reducing their dependence on on-premises Active Directory and adopting cloud-native capabilities in Microsoft Entra ID. Whether the goal is complete Active Directory retirement or a smaller, more secure on-premises footprint, this guidance helps you plan and execute that transformation.
1 August 2026: Custom-branding CSS retirement is the clearest action; Conditional Access enforcement and tenant-governance guidance are the other key signals
Two Microsoft Entra ID Message Center items carry the greatest operational weight. Microsoft Entra ID will retire custom CSS positioning properties in company branding starting in October 2026, while a Conditional Access notice gives 15 June 2026 as the start date for stronger enforcement of policies targeting All resources with exclusions in certain scope-only sign-ins. The remaining notable changes are documentation and architecture guidance: Tenant Governance baseline and drift-monitoring procedures, a new tenant-estate architecture set, and Internet Access/Defender for Cloud Apps coexistence instructions. The supplied evidence does not establish a GA or feature launch for those Learn updates.
- Retirement: custom CSS positioning in Microsoft Entra company branding
Entra ID · Authentication
Microsoft Entra ID will retire support for custom CSS positioning properties in company branding starting in October 2026 as a security and phishing-resistance measure. Existing users must remove those properties, with no migration path provided; branding elements will remain visible but can return to default placement.
- Changed behavior: Conditional Access enforcement for resource exclusions
Entra ID · Conditional Access
A Message Center notice states that, starting 15 June 2026, Conditional Access policies targeting All resources with exclusions will be enforced for sign-ins requesting only certain OIDC or directory scopes. Custom applications using only those requests may encounter new challenges such as MFA. Because the stated date precedes this reporting period, affected app owners should evaluate current sign-in behavior; the notice says most organizations need no action.
- Tenant Governance documentation now connects snapshots, drift monitoring, and permissions
ID Governance · Governance
A new Microsoft Entra Tenant Governance article documents configuration snapshots for tenant baselines or audit evidence. Related updates cover monitors that evaluate a tenant against a baseline and report configuration drift, viewing results, end-to-end deployment, and the application permissions and roles used by the configuration-management service. The evidence describes a procedural documentation expansion, not a stated preview, GA, or service-behavior change.
- New guidance for composing a Microsoft Entra tenant estate
Entra ID · Architecture
A new architecture-guidance set introduces common tenant patterns intended to help organizations meet requirements with as few tenants as possible. Companion guidance covers primary production, nonproduction multitenant environments, collaborating production tenants, business-partner access, critical business systems, and hybrid identity and isolation. It is design guidance for comparing architectural options, not evidence of a mandatory tenant restructuring.
- New coexistence guidance for Microsoft Entra Internet Access and Defender for Cloud Apps
Internet Access · General
A new article explains how to configure Microsoft Entra Internet Access alongside Microsoft Defender for Cloud Apps without proxying traffic twice. This is targeted operational guidance for environments using both products, rather than an announced launch or availability change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
19 updates
Microsoft Entra ID
10 updatesLearn about Microsoft Entra tenant architecture for collaborating production tenants so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for nonproduction environments so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for primary production tenants so that you can identify your needs and compare architectural options.
Learn how to compose your Microsoft Entra tenant estate from common tenant architecture patterns so that you can meet your requirements with as few tenants as possible.
Learn about Microsoft Entra tenant architecture for business partner access so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for critical business systems so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for hybrid identity and isolation so that you can identify your needs and compare architectural options.
Instructions about how to find Microsoft Entra ID and how to create a new tenant for your organization.
> [!NOTE]
Microsoft Entra ID Governance
8 updatesLearn how to create configuration snapshots in Microsoft Entra Tenant Governance to capture tenant configuration for baselines or audit evidence
Learn how to view monitor results and configuration drifts and manage configuration monitors in Microsoft Entra Tenant Governance
Learn how to create a configuration monitor in Microsoft Entra Tenant Governance to evaluate a tenant against a configuration baseline and report drift
This article walks you through managing unsponsored guests using the **Unsponsored guest cleanup (Preview)** workflow template.
Learn how to deploy Microsoft Entra Tenant Governance from setup through tenant discovery, governance, and configuration monitoring
Learn how to assign or remove the application permissions and roles that the Tenant Configuration Management service uses to create snapshots and run monitors
Learn how to securely create a governed Microsoft Entra workforce tenant and establish governance from your home tenant.
When you create a new Microsoft Entra tenant using the secure add-on tenant creation feature, you're prompted to select an existing subscription and resource group from your billing account. When you create your new tenant, Microsoft generates a new billing asset called **Entra ID Free** under that subscription and resource group, which links to the newly created tenant.
Microsoft Entra Internet Access
1 updateLearn how to configure Microsoft Entra Internet Access and Microsoft Defender for Cloud Apps side by side without proxying traffic twice.
