Tenant customization is not a visual exercise. It’s an identity design decision that shapes how users interpret legitimacy, authority, and intent – long before a device is fully managed.
When branding is treated as optional or deferred, users are trained to ignore context. That behavior becomes a liability once security controls depend on user recognition and trust. A user who can’t distinguish a real sign-in prompt from a phishing page isn’t a training failure – it’s a design failure.
Customization in a modern Intune environment doesn’t live in one place. It appears across three distinct surfaces that users encounter at different points in their day, each answering a different question and each serving a different purpose. Understanding why those surfaces exist separately is more important than knowing how to configure them.
Identity branding governs what users see at the most sensitive moment in the lifecycle: authentication. This is where users decide whether something feels legitimate.
The Entra ID sign-in experience is the first surface. It appears before access is granted and before device posture is evaluated. A branded sign-in page does more than display a logo – it provides continuity across Microsoft services, ensures error and access-denied messages look intentional, and frames MFA prompts as expected security behavior rather than interruptions. When users repeatedly see a consistent sign-in experience, they develop pattern recognition. Anything that deviates from that pattern becomes suspicious. Without this consistency, users are conditioned to accept generic login screens as normal, which erodes the effectiveness of every downstream control.
The Company Portal is the second surface. Once authentication is complete, users shift from identity interaction to device interaction. The Company Portal is the visible face of device management – it communicates who manages the device, what support looks like, and why certain actions are required. Branding here reinforces that device controls are deliberate and centrally governed, not arbitrary restrictions imposed by software. Support messaging and consistent visual identity reduce friction when users encounter compliance prompts or installation delays. Instead of questioning legitimacy, users understand where the control originates and how to get help.
The third surface is browser-level branding, which closes a gap that the other two surfaces don’t cover. When users access Microsoft 365 services through a browser, the experience sits between identity and device management. Consistent branding here – particularly around new tab pages and browser profiles – maintains the visual thread that the other surfaces establish.
Each surface answers a different question for the user. Letting them drift apart – visually or contextually – trains users to treat each one as a separate, unrelated system.
The mistake I see most often is treating these surfaces as independent configuration tasks rather than a connected system. Organizations brand the sign-in page and leave the Company Portal on defaults. Or they configure the portal carefully and never touch the browser experience. The gaps between surfaces are where user trust erodes – not dramatically, but gradually, through repeated exposure to inconsistency.
This decision needs to be made before enrollment begins because the sign-in experience is the first thing users see. First impressions establish the baseline for what normal looks like. The next article covers implementation – where each of these surfaces is configured and what decisions matter most in practice.
Intune Deployment Guide · Phase 2: Identity and Tenant Foundation
‹ Previous: [2.1] Getting Your Azure House in Order
Next: [2.1.2] Implementing Tenant Customization and Branding ›




