Organizations are increasingly modernizing identity, access, and device management by reducing their dependence on on-premises Active Directory and adopting cloud-native capabilities in Microsoft Entra ID. Whether the goal is complete Active Directory retirement or a smaller, more secure on-premises footprint, this guidance helps you plan and execute that transformation.
Custom-branding CSS retirement and SMS/voice authentication phase-out lead the week
The week of 27 July 2026 is driven more by retirements, security guidance, and changed behavior than by a broad feature launch. Microsoft Entra ID has a Message Center retirement for custom CSS positioning in company branding beginning October 2026. Updated guidance prepares public-cloud tenants for the retirement of Microsoft-provided SMS and voice authentication and migration to passkeys. A separate Conditional Access notice describes stronger enforcement for certain narrow-scope sign-ins. Workload ID guidance moves GitHub Actions federated credentials toward immutable subjects. ID Governance also received substantial Tenant Governance guidance covering snapshots, configuration drift monitoring, related-tenant signals, and a Microsoft Graph preview; the supplied evidence does not establish a new GA launch for those documentation updates.
- Custom branding CSS positioning properties retire in October 2026
Entra ID · Authentication
This Microsoft 365 Message Center major update affects Microsoft Entra ID company branding, not just documentation. Support for custom CSS positioning properties is scheduled to retire starting October 2026. Existing users must remove those properties; there is no migration path, and branding elements may remain visible but revert to default placement. Administrators should inventory affected branding configurations and plan their removal before the stated deadline.
- Microsoft-provided SMS and voice authentication guidance shifts users toward passkeys
Entra ID · Authentication
An updated Microsoft Entra ID article explains how to prepare for retirement of Microsoft-provided SMS and voice authentication and migrate users to passkeys. The supplied timeline clarification applies to public cloud only; other cloud environments will follow later schedules with advance communications. Separately, a Message Center notice says passkey registration optimizations across Registration Campaign, Authentication Strengths, and My Sign-Ins will roll out in late August 2026, prioritize local-device passk
- Conditional Access enforcement changes for policies with resource exclusions
Entra ID · Conditional Access
A Message Center notice says that, starting June 15, 2026, Conditional Access policies targeting All resources with exclusions are enforced for sign-ins requesting only certain OIDC or directory scopes. Some users may encounter new challenges such as MFA. Most organizations need no action, but custom applications that request only the affected scopes should be evaluated. This is a changed-behavior notice, not a new Conditional Access feature launch.
- GitHub Actions federated credentials should use immutable subjects
Workload ID · Security
New and updated Workload ID security guidance explains that mutable OIDC subject claims expose federated identity credentials to subject recycling, while immutable claims reduce that risk. For GitHub Actions, the guidance covers migrating to GitHub's immutable subject format and creating a separate credential for each subject a workflow presents, such as a branch or environment. Organizations using these credentials should review their current subject configuration; no migration deadline is supplied.
- Tenant Governance documentation adds snapshots, drift monitoring, and related-tenant investigation
ID Governance · Governance
New and updated ID Governance guidance now covers creating configuration snapshots for baselines or audit evidence, configuring monitors to evaluate a baseline and report drift, viewing monitor results, and assigning the service permissions and roles needed for those operations. Related-tenant guidance also explains how to use Microsoft Graph in preview to retrieve the users and applications behind tenant-discovery signals. These entries document an operational workflow and a preview API; they are not evidence of a
Treat the branding and authentication items as planning work: identify custom CSS positioning properties, assess public-cloud users who still rely on Microsoft-provided SMS or voice authentication, and review GitHub Actions federated credentials that use mutable subjects. Evaluate custom applications requesting only the OIDC or directory scopes covered by the Conditional Access notice. If adopting Tenant Governance, review the application permissions and roles required for snapshots and monitors, and note that the Graph-related capability is marked preview. The passkey-registration optimization notice says organizations need no action; the other tenant-architecture, workflow, and setup changes are documentation guidance rather than confirmed service changes.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
17 updatesLearn about Microsoft Entra tenant architecture for collaborating production tenants so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for nonproduction environments so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for primary production tenants so that you can identify your needs and compare architectural options.
Learn how to compose your Microsoft Entra tenant estate from common tenant architecture patterns so that you can meet your requirements with as few tenants as possible.
Learn about Microsoft Entra tenant architecture for business partner access so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for critical business systems so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for hybrid identity and isolation so that you can identify your needs and compare architectural options.
Microsoft Entra ID will retire support for custom CSS positioning properties in company branding starting October 2026 to enhance security and phishing resistance. Existing users must remove these properties by then, as no migration path exists. Branding elements remain visible but may revert to default placement.
Sms Voice Retirement
UpdatedThis timeline applies to public cloud environments only. Other cloud environments will follow on a later schedule, and we will provide advance communications to help customers prepare for the transition.
Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys.
Microsoft Entra ID is optimizing passkey registration via Registration Campaign, Authentication Strengths, and My Sign-Ins to improve compliance with passkey policies and prioritize local device passkeys. These changes, rolling out in late August 2026, require no user interface changes or action from organizations.
Starting June 15, 2026, Conditional Access policies targeting All resources with exclusions will be enforced for sign-ins requesting only certain OIDC or directory scopes. Some users may face new challenges like MFA. Most organizations need no action, but custom apps requesting only these scopes should be evaluated.
Instructions about how to find Microsoft Entra ID and how to create a new tenant for your organization.
Prerequisites
Updated- Microsoft Entra Cloud Sync agent must be installed on a domain-joined server. We recommend using Windows Server 2025 or Windows Server 2022. You can also deploy Microsoft Entra Cloud Sync on older Windows Server versions that are in extended support; however, support for this configuration may require [a paid support program](/lifecycle/policies/fixed#extended-support).
> [!NOTE]
Connect Health Agent Install
Updated> If you have a highly locked-down and restricted environment, you need to add more URLs than the URLs the table lists for Internet Explorer enhanced security. Also add URLs that are listed in the table in the next section.
Microsoft Entra ID Governance
16 updatesLearn how to create configuration snapshots in Microsoft Entra Tenant Governance to capture tenant configuration for baselines or audit evidence
Learn how to view monitor results and configuration drifts and manage configuration monitors in Microsoft Entra Tenant Governance
Learn how to create a configuration monitor in Microsoft Entra Tenant Governance to evaluate a tenant against a configuration baseline and report drift
This article walks you through managing unsponsored guests using the **Unsponsored guest cleanup (Preview)** workflow template.
Learn how to deploy Microsoft Entra Tenant Governance from setup through tenant discovery, governance, and configuration monitoring
Learn how to assign or remove the application permissions and roles that the Tenant Configuration Management service uses to create snapshots and run monitors
Learn how to securely create a governed Microsoft Entra workforce tenant and establish governance from your home tenant.
When you create a new Microsoft Entra tenant using the secure add-on tenant creation feature, you're prompted to select an existing subscription and resource group from your billing account. When you create your new tenant, Microsoft generates a new billing asset called **Entra ID Free** under that subscription and resource group, which links to the newly created tenant.
Learn how to use Microsoft Graph to retrieve the underlying users and applications behind Tenant Governance related tenant discovery signals.
Lifecycle Workflow Tasks
UpdatedWith customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. You can include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. The list of dynamic attributes that can be included are as follows:
Customize Workflow Email
UpdatedIn the message body, you can customize the email text to personalize it for each recipient. You can optionally include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes by embedding them in the text. Before the email is sent, the placeholders are replaced with the actual user information.
Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants
Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization
Learn about cross-tenant delegated administration and the GDAP-based permission model for managing tenants in Microsoft Entra.
Learn how to use cross-tenant delegated administration to sign in to and manage governed tenants using your governing tenant credentials
Governance Policy Templates
Updated- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.
Microsoft Entra External ID
1 updateLearn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
Microsoft Entra Internet Access
2 updatesGsa Poc Internet Access
Updated1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.
Learn how to configure Microsoft Entra Internet Access and Microsoft Defender for Cloud Apps side by side without proxying traffic twice.
Microsoft Entra Workload ID
4 updates"audiences": ["api://AzureADTokenExchange"]
Learn how to migrate a Microsoft Entra federated identity credential for GitHub Actions from a mutable subject to GitHub's immutable subject format.
Learn how mutable OIDC subject claims expose Microsoft Entra federated identity credentials to subject recycling, and how immutable claims reduce the risk.
Replace `<application-object-id>` with the object ID of your app registration. Create one credential for each subject the workflow presents, such as a different branch or environment.
Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
