Microsoft will begin adding browser-based protections against external script injection during Entra ID sign-ins in mid-October 2026. The rollout is expected to finish by late October, according to a Monday message center update seen by BleepingComputer.
The new Content Security Policy (CSP) will allow scripts only from trusted Microsoft content delivery network (CDN) domains during authentication. Microsoft says the change is intended to help protect against threats including cross-site scripting (XSS), which can inject malicious code into websites to steal credentials. The company first announced plans to secure Entra ID sign-ins from script injection in November 2025.
Microsoft advised enterprise customers to stop using browser extensions and other tools that inject code into sign-in pages before the policy takes effect. It also urged administrators to test sign-in flows for dependencies on those tools. Potential CSP violations can be checked in the browser developer console, where blocked scripts appear in red text.
Users will still be able to sign in if unsupported injection tools stop working. The change is enabled by default and requires no tenant configuration. Microsoft Authentication Library (MSAL) and API-based authentication flows are unaffected; enforcement applies to browser-based sign-ins using login.microsoftonline.com.
Microsoft said the change is part of its Secure Future Initiative (SFI). The company announced the initiative after Chinese hackers breached Exchange Online mailboxes in May and June 2023.
Comments
0No comments yet. Be the first to comment.