Microsoft Entra ID is retiring custom CSS positioning properties to help deliver more secure and trusted branded sign-ins. [Action may be required]
To align with Microsoft’s Secure Future Initiative and its focus on identity security and phishing resistance, we’re evolving Microsoft Entra custom branding to help customers deliver sign-in experiences that are more secure, reliable, and consistent.
Beginning October 26, 2026, Microsoft Entra will retire support for custom CSS positioning properties used in custom branding. Full retirement of all custom CSS is planned for later in 2027. Microsoft will provide advance notice ahead of this milestone, along with alternative customization options.
These changes add an additional layer of security by reducing opportunities for deceptive page layouts and helping ensure trusted, recognizable sign-in experiences that better protect users from phishing attacks.
When will this happen?
- July 21, 2026: Microsoft Entra ID tenants not using custom CSS positioning properties before July 21, 2026, will not be able to configure them going forward.
- October 26, 2026: Microsoft Entra ID will retire custom CSS positioning properties globally.
- Later in 2027: Microsoft Entra plans to move towards full custom CSS retirement, with advance notice provided.
Who will be affected?
To retire support for positioning properties, Microsoft is helping prevent tenants from creating new dependencies on custom CSS:
- Tenants that will be affected and need to take action by October 26, 2026:
- Microsoft Entra ID tenants that already use custom CSS positioning properties. After this date, these properties will be blocked and will no longer function.
- Tenants that are not affected:
- Microsoft Entra ID tenants that do not already use custom CSS positioning properties will not be able to configure them after July 21, 2026.
- New Microsoft Entra ID tenants created after January 5, 2026, do not have custom CSS available for custom branding.
- Microsoft Entra External ID tenants.
How will this affect your organization?
Microsoft Entra ID customers using the deprecated positioning properties may see changes to the layout of their branded sign-in experience after October 26, 2026, and won’t have a supported migration or replacement. In most cases, branding elements such as logos, images, or text will remain visible but will appear in their default state once the positioning properties are no longer honored.
If your Microsoft Entra ID tenant uses any of these custom CSS positioning properties below in either Company Branding or Branding Themes , we recommend removing them from your configuration:
- position (including top, right, bottom, left, and z-index)
- margin (including margin-top, margin-bottom, margin-left, and margin-right)
- transform
- opacity
- overflow
- filter
- pointer-events
- clip-path
- mix-blend-mode
- translate
Microsoft Entra ID customers who use the properties above will be notified directly in advance.
What do you need to do to prepare?
To determine whether your tenant uses positioning properties and requires you to take action:
- Make sure you use a global administrator or branding administrator role.
- Navigate to MS Graph Explorer
- Sign in into your tenant using the 'profile/sign in' button at the top right corner.
- If you have your tenantID, skip to step 5. Otherwise, you can get this by sending a GET request to the organization resource on the MS Graph Explorer. To do this, enter https://graph.microsoft.com/v1.0/organization and run the query. Then, copy the “id” value of the response.
- Get all the configured company branding locales by sending a GET request to the branding resource. To do this, enter https://graph.microsoft.com/v1.0/organization/<your tenant ID here>/branding/localizations and run the query.
- Copy the contents of the response or export it to a JSON file
- Navigate to this tool
- Paste the contents from step 6 or upload the exported JSON file to the input in the tool. You should get a list of locales and the properties impacted for each locale. These properties will be deprecated and are encouraged to be removed from your configuration.
Next steps
With these updates, Microsoft Entra custom branding continues to evolve as part of our proactive investment in secure, trusted, and consistent sign-in experiences.
To ensure a smooth transition, we encourage you to review your custom CSS configurations and remove any affected properties ahead of time. This will help you catch and address potential layout issues early, so your users stay protected and your branded sign-in experience remains seamless.
We’ll provide advance notice, guidance, and alternative customization options before broader custom CSS retirement. Thank you for your partnership as we make this transition.
-Adam Steenwyk
Principal Lead Product Manager, Microsoft Identity, Authentication Experiences
Additional resources
- Custom CSS overview
- Customize the sign-in experience for your application with branding themes
- Configure your Company Branding
- Microsoft Secure Future Initiative (SFI)
Learn more about Microsoft Entra
Prevent identity attacks, ensure least-privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and cloud environments.