Week in brief

Custom-branding CSS retirement and SMS/voice authentication phase-out lead the week

The week of 27 July 2026 is driven more by retirements, security guidance, and changed behavior than by a broad feature launch. Microsoft Entra ID has a Message Center retirement for custom CSS positioning in company branding beginning October 2026. Updated guidance prepares public-cloud tenants for the retirement of Microsoft-provided SMS and voice authentication and migration to passkeys. A separate Conditional Access notice describes stronger enforcement for certain narrow-scope sign-ins. Workload ID guidance moves GitHub Actions federated credentials toward immutable subjects. ID Governance also received substantial Tenant Governance guidance covering snapshots, configuration drift monitoring, related-tenant signals, and a Microsoft Graph preview; the supplied evidence does not establish a new GA launch for those documentation updates.

  • This Microsoft 365 Message Center major update affects Microsoft Entra ID company branding, not just documentation. Support for custom CSS positioning properties is scheduled to retire starting October 2026. Existing users must remove those properties; there is no migration path, and branding elements may remain visible but revert to default placement. Administrators should inventory affected branding configurations and plan their removal before the stated deadline.

  • An updated Microsoft Entra ID article explains how to prepare for retirement of Microsoft-provided SMS and voice authentication and migrate users to passkeys. The supplied timeline clarification applies to public cloud only; other cloud environments will follow later schedules with advance communications. Separately, a Message Center notice says passkey registration optimizations across Registration Campaign, Authentication Strengths, and My Sign-Ins will roll out in late August 2026, prioritize local-device passk​

  • A Message Center notice says that, starting June 15, 2026, Conditional Access policies targeting All resources with exclusions are enforced for sign-ins requesting only certain OIDC or directory scopes. Some users may encounter new challenges such as MFA. Most organizations need no action, but custom applications that request only the affected scopes should be evaluated. This is a changed-behavior notice, not a new Conditional Access feature launch.

  • New and updated Workload ID security guidance explains that mutable OIDC subject claims expose federated identity credentials to subject recycling, while immutable claims reduce that risk. For GitHub Actions, the guidance covers migrating to GitHub's immutable subject format and creating a separate credential for each subject a workflow presents, such as a branch or environment. Organizations using these credentials should review their current subject configuration; no migration deadline is supplied.

  • New and updated ID Governance guidance now covers creating configuration snapshots for baselines or audit evidence, configuring monitors to evaluate a baseline and report drift, viewing monitor results, and assigning the service permissions and roles needed for those operations. Related-tenant guidance also explains how to use Microsoft Graph in preview to retrieve the users and applications behind tenant-discovery signals. These entries document an operational workflow and a preview API; they are not evidence of a

For Entra administrators

Treat the branding and authentication items as planning work: identify custom CSS positioning properties, assess public-cloud users who still rely on Microsoft-provided SMS or voice authentication, and review GitHub Actions federated credentials that use mutable subjects. Evaluate custom applications requesting only the OIDC or directory scopes covered by the Conditional Access notice. If adopting Tenant Governance, review the application permissions and roles required for snapshots and monitors, and note that the Graph-related capability is marked preview. The passkey-registration optimization notice says organizations need no action; the other tenant-architecture, workflow, and setup changes are documentation guidance rather than confirmed service changes.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

8

Road to the cloud: Introduction

Updated

Organizations are increasingly modernizing identity, access, and device management by reducing their dependence on on-premises Active Directory and adopting cloud-native capabilities in Microsoft Entra ID. Whether the goal is complete Active Directory retirement or a smaller, more secure on-premises footprint, this guidance helps you plan and execute that transformation.

1 August 2026
4

Sms Voice Retirement

Updated

This timeline applies to public cloud environments only. Other cloud environments will follow on a later schedule, and we will provide advance communications to help customers prepare for the transition.

31 July 2026
1
1
1

Prerequisites

Updated

- Microsoft Entra Cloud Sync agent must be installed on a domain-joined server. We recommend using Windows Server 2025 or Windows Server 2022. You can also deploy Microsoft Entra Cloud Sync on older Windows Server versions that are in extended support; however, support for this configuration may require [a paid support program](/lifecycle/policies/fixed#extended-support).

30 July 2026
1
1

Connect Health Agent Install

Updated

> If you have a highly locked-down and restricted environment, you need to add more URLs than the URLs the table lists for Internet Explorer enhanced security. Also add URLs that are listed in the table in the next section.

29 July 2026
16

Create configuration snapshots

New

Learn how to create configuration snapshots in Microsoft Entra Tenant Governance to capture tenant configuration for baselines or audit evidence

1 August 2026

Create a configuration monitor

Updated

Learn how to create a configuration monitor in Microsoft Entra Tenant Governance to evaluate a tenant against a configuration baseline and report drift

1 August 2026

Create a governed workforce tenant

Updated

Learn how to securely create a governed Microsoft Entra workforce tenant and establish governance from your home tenant.

1 August 2026

Automatic Governance Relationships

Updated

When you create a new Microsoft Entra tenant using the secure add-on tenant creation feature, you're prompted to select an existing subscription and resource group from your billing account. When you create your new tenant, Microsoft generates a new billing asset called **Entra ID Free** under that subscription and resource group, which links to the newly created tenant.

1 August 2026

Lifecycle Workflow Tasks

Updated

With customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. You can include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. The list of dynamic attributes that can be included are as follows:

30 July 2026

Customize Workflow Email

Updated

In the message body, you can customize the email text to personalize it for each recipient. You can optionally include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes by embedding them in the text. Before the email is sent, the placeholders are replaced with the actual user information.

30 July 2026

Interpret tenant discovery data

Updated

Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants

30 July 2026

Related tenants in Tenant Governance

Updated

Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization

30 July 2026

Governance Policy Templates

Updated

- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.

30 July 2026
1

Add OIDC for customer sign-in

Updated

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

30 July 2026
1

Gsa Poc Internet Access

Updated

1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.

30 July 2026
1
3
1

Workload Identities Github Immutable Subjects

Updated

Replace `<application-object-id>` with the object ID of your app registration. Create one credential for each subject the workflow presents, such as a different branch or environment.

31 July 2026
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…