Microsoft Entra ID is restricting custom branding for sign-in pages. Beginning October 26, 2026, custom CSS layout and positioning properties will be blocked globally. Organizations that styled their Microsoft 365 sign-in experience with custom CSS should review it now. Logos, images, and text generally remain available, but affected rules for positioning, spacing, visibility, or overlapping content will no longer work. For small and midsize organizations, this is an operational and security issue: an unexpected change can create support requests and reduce confidence in the login experience.
What Microsoft is changing for branded sign-ins
Microsoft connects the change to its Secure Future Initiative and the goal of making sign-in experiences more secure, reliable, and consistent. Layout and positioning properties can move, overlap, resize, or hide page content. Blocking them is intended to keep layouts predictable and reduce opportunities for deceptive presentation. The change affects Microsoft Entra ID tenants that already use these properties in Company Branding or Branding Themes. According to Microsoft’s announcement, Microsoft Entra External ID tenants aren’t affected.
This retirement is also the first step toward removing the custom CSS feature completely. Full retirement is planned for later in 2027. Microsoft says it will provide advance notice and alternative customization options before that milestone. The October deadline already has a defined technical consequence: the listed properties will be blocked and no longer honored.
Which CSS rules are affected
The list is much broader than position. It includes properties that control arrangement, spacing, visibility, transformations, and interaction. Microsoft provides no supported direct replacement for them. Existing logos, images, and text generally won’t disappear, but they can return to their default state or appear in a different location after the cutoff.
- Positioning and layering rules such as
position,top,z-index,display, andvisibility. - Spacing and grid rules, including
margin, logical margin properties,grid-row, andgrid-column. - Transforms and visual effects such as
transform,scale,rotate,opacity, andfilter. - Overflow, masking, and interaction rules including
overflow,clip-path,mask, andpointer-events.
Why the change matters to SMBs
Many SMBs configure branding once during a Microsoft 365 rollout and rarely inspect it afterward. Older customizations are where affected rules can remain unnoticed. Localized versions require attention too: the English page might look normal while another language still uses older CSS. If users report the change first, administrators must troubleshoot configuration, rendering, and user perception under time pressure.
The task belongs in the technical maintenance of Microsoft Entra ID; it is not a licensing decision. Organizations should document which branding variants are active, which rules Microsoft will block, and how each page looks without them. It is also sensible to include Conditional Access in the test plan. The policies themselves don’t change, but sign-in messaging and recognition should be checked alongside the access journey.
Deadline: what must happen by October 26, 2026
Tenants using affected layout or positioning properties need to remove them by October 26, 2026. Since July 21, 2026, older tenants that hadn’t previously used custom CSS can no longer configure it. New Microsoft Entra ID tenants created after January 5, 2026, don’t have custom CSS available at all. Microsoft says affected existing customers will also receive direct notifications. Organizations shouldn’t rely on that message alone, because configurations can be spread across multiple languages and Branding Themes.
Next steps for administrators
Microsoft documents two review paths. Administrators can download the current CSS from Custom branding in the Entra admin center. To cover all localized variants, they can export the branding configuration through Microsoft Graph and analyze it with the tenant branding inspector linked by Microsoft. Exporting and changing the configuration requires an appropriate administrator role.
- Inventory every Company Branding configuration and Branding Theme, including localized versions.
- Export the CSS files and search specifically for every property Microsoft lists as deprecated.
- Remove affected rules and validate the visual impact in a test tenant first.
- Test sign-ins with representative browsers, languages, and screen sizes before the deadline.
- Record results, owners, and rollback steps in a Microsoft Security Assessment or your internal change process.
Official Microsoft sources
- Microsoft Entra Blog: Microsoft Entra ID enhances security of branded sign-ins
- Microsoft Learn: CSS reference guide for customizing company branding
If it is unclear which Entra customizations are active in your tenant, a focused technical inventory can establish the facts. ReByteIT reviews branding, sign-in paths, and related security settings and turns the findings into concrete work before the deadline – get in touch.
What does this mean for your environment?
Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.
