Protect.Computer
NEWS

Microsoft Entra ID to Block Script Injection on Sign-In Pages

· 1 min read · Identity theft Network safety
Microsoft Entra ID to Block Script Injection on Sign-In Pages

Microsoft has reminded customers that starting in mid-October 2026 it will enforce a Content Security Policy (CSP) on Entra ID sign-in pages that only allows scripts served from trusted Microsoft content delivery domains. The rollout should finish by late October. The goal is to stop cross-site scripting and other attacks that inject malicious code into the login flow to steal credentials, and it follows a plan first announced in November 2025 under Microsoft’s Secure Future Initiative.

The change is on by default and needs no tenant configuration. Its side effect is that anything that injects scripts into sign-in pages will stop working, including some browser extensions, password-manager or branding tools, and in-house customizations. Users can still sign in; the injected tooling just won’t run. Microsoft says MSAL and API-based authentication flows are not affected, because enforcement applies only to browser sign-ins on login.microsoftonline.com.

IT teams have about two weeks to find dependencies. Microsoft’s advice is to test sign-in scenarios now and check the browser developer console during login for CSP violations, which show up as red errors naming the blocked script.

Sources

Related reading