Microsoft Entra External Microsoft SSO sign in page

Lisa 60 Reputation points
2026-05-08T13:06:22.6566667+00:00

Hello,

We are using Microsoft Entra External as an identity provider. We use the Google and Apple identity providers in our user flow and these are working fine. However for the Microsoft sign in flow we have a couple of questions:

Custom background

We've set up a custom background for our Microsoft sign in page through our Company branding. However, we have decided we would like to revert to the default Microsoft branding. When trying this, we have removed our custom background, but that did not result in the default background returning. Instead, we now have a simple white background. How can we make it so the default background returns?

Hide Google and Apple from sign in

We allow our users to sign in with Google and Apple. On our custom sign in page, we have buttons for each sign in method that directly navigate to Google and Apple respectively using MSAL for React. This works very nicely, however when users click the "sign in with Microsoft" button, they're presented with our Microsoft sign in page, which also lists the options to sign in with Google and Apple. We would like to not show those options and let the user only sign in with Microsoft on this page. We believe they show up because we have configured these methods for our user-flow under the External Identities. Removing them there will remove them from the Microsoft page, but also not allow users to sign in with Google and Apple anymore. Is there a way that we can hide the Google and Apple sign methods only from the Microsoft page, while still being able to sign the users in with Google and Apple using MSAL for React?

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

Answer accepted by question author
VEMULA SRISAI 14,065 Reputation points Microsoft External Staff Moderator
2026-05-08T13:53:10.49+00:00

Hello Lisa,

Thank you for the detailed information.

Regarding the custom background behavior, what you are currently seeing is expected with the newer Microsoft Entra External ID branding experience. After removing a custom background image, the sign-in page falls back to the default neutral/white background rather than restoring the previous Microsoft stock illustration. At this time, there is no supported configuration available to restore the old default Microsoft background image automatically.

For the identity provider behavior, the Google and Apple options appear because those identity providers are enabled within the same user flow. In Microsoft Entra External ID, all enabled identity providers configured for a user flow are automatically displayed on the Microsoft-hosted sign-in page.

Currently, there is no supported feature to selectively hide Google and Apple providers only from the Microsoft sign-in page while still keeping them enabled in the same user flow.

Your understanding regarding user flows is correct. An application can only be associated with one user flow through the standard configuration experience. Because of this limitation, if separate sign-in experiences are required (for example, Microsoft-only on one page and Google/Apple on another), this would typically require a custom implementation approach such as custom policies or a redesigned authentication flow architecture.

Reference documentation:

https://learn.microsoft.com/en-us/entra/external-id/customers/concept-branding-customers

https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-user-flow-add-application

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-05-08T13:06:52.0766667+00:00

    Two separate behaviors are involved here: branding for External ID tenants and how identity providers are surfaced in user flows.

    1. Default vs custom background/branding

    In an External ID tenant, the default experience is a neutral, non-Microsoft-branded sign-in page. After creating the external tenant, this neutral branding can be customized (background image/color, favicon, layout, header, footer, CSS). If custom branding fails to load, the page reverts to this neutral branding.

    Because the default for External ID is neutral branding (not the Microsoft Entra ID “blue” background), removing custom branding returns the experience to that neutral look, which is why a plain/white-style background appears. There is no option in External ID to revert to the Microsoft Entra ID default Microsoft branding; the supported options are:

    • Neutral (default) branding, or
    • Custom branding defined in the external tenant.

    To change what you see, re-apply or adjust custom branding in the external tenant (for example, upload a background image or CSS) rather than expecting the Microsoft default background to return.

    2. Hiding Google/Apple on the Microsoft sign-in page only

    In External ID, sign-in methods and external identity providers are configured per user flow. When Google and Apple are enabled as identity providers in a user flow, they appear as options on the Microsoft-hosted sign-in page for that flow. The platform does not support hiding those providers only on the Microsoft page while still having them enabled in the same user flow.

    Key points from the platform behavior:

    • User flows define the sign-in methods and external IdPs (Google, Facebook, Apple, Entra ID federation, custom OIDC) that are available to customers.
    • When those IdPs are enabled, they are surfaced as options in the sign-in experience for that user flow.
    • Changing sign-in methods or IdPs in a user flow affects how new users sign up/sign in; there is no per-page toggle to hide specific IdPs only on the Microsoft sign-in screen.

    Given this, the supported configuration options are:

    • Keep Google and Apple enabled in the user flow: they will appear on the Microsoft sign-in page and be available to MSAL-based flows.
    • Remove Google and Apple from the user flow: they will not appear on the Microsoft sign-in page, but they also will not be available as sign-in methods for that flow.

    The platform does not provide a built-in way to:

    • Show Google/Apple only when starting from custom MSAL UI, and
    • Hide them when the same user flow is rendered on the Microsoft-hosted page.

    To achieve more granular control over what is shown where, the supported approaches are:

    • Use separate user flows with different IdP configurations and route users accordingly from the application, or
    • Move to a more advanced/customized model (for example, native authentication or custom extensions) where the app owns more of the UX and calls the External ID endpoints accordingly.

    However, with the standard user-flow-based External ID sign-in page, hiding Google and Apple only on the Microsoft page while still using them in that same flow is not supported.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.