Microsoft Is About to Block Injected Scripts on Entra ID Sign-Ins
Microsoft is tightening Entra ID sign-in security with new Content Security Policy protections that will block unsupported script injection during browser-based authentication.
The changes will begin rolling out in mid-October 2026 and should reach all users by late October, according to Message Center MC1481309.
Microsoft will block injected scripts on Entra ID sign-in pages
The new Content Security Policy, or CSP, will restrict which scripts can run during Entra ID authentication. Microsoft will allow scripts hosted on trusted Microsoft CDN domains while blocking externally injected scripts.
Microsoft says the additional protection can reduce the risk from attacks such as cross-site scripting, or XSS, where malicious code can enter a sign-in page and potentially capture credentials.
The policy will apply automatically, so administrators will not need to enable or configure it manually.
Browser extensions and injected tools could stop working
Microsoft is warning organizations to stop relying on browser extensions or other tools that inject scripts or code into Entra ID sign-in pages before enforcement begins.
Enterprises should test their existing authentication workflows to identify extensions, automation tools, or other dependencies that rely on unsupported script injection.
Administrators can also inspect the browser developer console for CSP violations. These warnings can identify scripts that the new policy would block once enforcement starts.
Users should still be able to sign in even when an affected browser extension or injected tool stops functioning.
The change only affects browser-based authentication
CSP enforcement will apply specifically to browser-based authentication experiences running through login.microsoftonline.com.
Microsoft Authentication Library, or MSAL, and API-based authentication flows will not be affected by the change.
Organizations using customized authentication workflows should review their sign-in environments before the October rollout to make sure unsupported injected scripts do not disrupt existing processes.
In other news, researchers recently detailed the TrustSink attack targeting Entra MFA logins, while Microsoft has also explained how enterprises can replace traditional VPNs with Entra Private Access.
Microsoft is also encouraging organizations to adopt Windows Autopilot Device Preparation for simplified enterprise device deployment.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages