Major Entra Change Requiring Action by Oct 26, 2026
The major Microsoft Entra changes tied to October 26 (based on current authoritative sources) fall into one clear category: retirement of custom CSS and layout properties used in Entra ID branded sign‑in pages. This is a security‑driven change under Microsoft’s Secure Future Initiative (SFI), and IT admins must take action before October 26, 2026.
Major Entra Change Requiring Action by Oct 26, 2026
Microsoft is retiring a large set of CSS layout and positioning properties used in Entra ID custom branding.
If your organization uses custom CSS for sign‑in branding, this change directly affects you.
Properties being retired
These include (not exhaustive here, but confirmed by Microsoft):
offset,offset-path,offset-distancemargin-block,margin-inlineand all their start/end variantsorder,grid-area,grid-column,grid-rowisolation,overflow-x,overflow-y,overflow-block,overflow-inlinecontent-visibility,clip,mask,mask-image,-webkit-mask,-webkit-mask-image
Why Microsoft is doing this
Microsoft found that malicious actors were abusing these layout properties to impersonate branded sign‑in pages, enabling phishing attacks.
This retirement is part of the Secure Future Initiative (SFI) to harden identity infrastructure.
What happens on October 26, 2026
Any retired CSS property will stop functioning.
Your branded elements will revert to default positions and behavior.
You must remove or replace these properties before the deadline to avoid broken layouts.
Next phase
Microsoft will fully retire all custom CSS in Entra ID by late 2027.
Required Admin Actions Before Oct 26
Microsoft advises:
Download your current custom CSS file from Entra ID branding settings.
Identify any use of the retired properties.
Remove or replace them with supported alternatives.
Test your sign‑in experience to ensure branding still appears correctly.
Notify users and stakeholders about any visual changes.
Other Entra Changes Happening Around October (Not Oct 26‑specific)
These are important but not tied to the Oct 26 deadline:
Windows Hello for Business & macOS Platform SSO become standalone MFA factors
Rollout begins early October 2026, completing late November.
No admin configuration required.
Microsoft retiring SMS/voice MFA delivery
Passkeys become default for SMS/voice users: Sept 1, 2026
Microsoft stops providing SMS/voice MFA delivery: Feb 1, 2027
Summary: What matters for Oct 26
Area | Deadline | Impact |
|---|---|---|
Custom CSS retirement (specific properties) | Oct 26, 2026 | Must remove retired CSS properties or branding breaks |
Full custom CSS retirement | Late 2027 | All custom CSS removed |
WHfB & macOS PSSO as standalone MFA | Early Oct–Nov 2026 | MFA behavior changes, fewer prompts |
SMS/voice MFA retirement | Feb 1, 2027 | Must migrate to passkeys or telecom provider |
.png)
Comments
Post a Comment