Loading...

Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection

Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection

Microsoft Entra ID will enhance authentication security by enforcing a Content Security Policy that blocks external script injection, allowing only trusted Microsoft scripts. This rollout begins mid-October 2026, affecting browser-based sign-ins on login.microsoftonline.com, with no impact on Entra External ID tenants. Introduction As part of Microsoft’s Secure Future Initiative, we’re updating our Content Security Policy for the Microsoft Entra ID sign-in experience. This change adds an extra layer of protection by allowing only scripts from trusted Microsoft domains to run during authentication, blocking unauthorized or injected external code. This proactive measure helps safeguard users against threats like cross-site scripting (XSS), further strengthening security for your organization. When this will happen General Availability (Production/Worldwide only): Rollout begins mid-October 2026 Expected completion by late October 2026 Periodic communications will be sent closer to release. How this affects your organization Who is affected: Organizations using browser-based sign-in experiences on URLs starting with login.microsoftonline.com. No impact to Microsoft Entra External ID tenants. What will happen: A new Content Security Policy header will be added to Microsoft Entra sign-in pages. Scripts will only be allowed from Microsoft trusted CDN domains. Inline script execution will only be allowed from trusted Microsoft sources. Browser extensions or tools that inject code into the sign-in page will stop working, though users can still sign in. What you can do to prepare If you do not use tools or extensions that inject code into the sign-in experience, no action is required. If you do use such tools, switch to alternatives that don’t inject code. Test your sign-in flows thoroughly before rollout to identify and resolve any issues early. Testing instructions can be found on our CSP Guide for Microsoft Entra ID. Learn more: Compliance considerations No compliance considerations identified; review as appropriate for your organization. Content Security Policy Overview for Microsoft Entra ID  Microsoft Entra ID Content Security Policy Public Blog Post on Techcommunity Microsoft Secure Future Initiative The CSP nonce guide | Content Security Policy (CSP) quick reference guide The CSP script-src directive guide | Content Security Policy (CSP) quick reference guide Why XSS still matters: MSRC’s perspective on […]

The post Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft OneDrive and SharePoint: Generate smart tables of contents for PDFs on the web with Copilot

Microsoft 365 Copilot users can generate AI-created, hierarchical, clickable tables of contents for PDFs in OneDrive and SharePoint on the web...

11 hours ago

Microsoft Defender for Office 365: Changes to Unified RBAC permission mapping for Microsoft Entra Security Operator role

Microsoft is updating Microsoft Defender for Office 365’s Unified RBAC mapping for the Microsoft Entra Security Operator role, removing ...

11 hours ago

Microsoft 365 Copilot: new guided Copilot onboarding experience

Microsoft 365 Copilot introduces an optional, admin-enabled guided onboarding experience for Frontier participants starting late October 2026....

11 hours ago

Microsoft Purview |Unified Classification Management Experience

Microsoft Purview is launching a unified Classification Management experience for admins to manage classifiers consistently. Public Preview st...

11 hours ago

Microsoft Purview | Data Loss Prevention: Administrative Units support for DLP policies for Microsoft Copilot

Microsoft Purview extends Microsoft Entra Administrative Units support to Copilot DLP policies, enabling delegated management within units whi...

11 hours ago

Action required: Update Teams devices to a minimum app version ahead of the retirement of Exchange Web Services (EWS)

Update Microsoft Teams Rooms on Android, phones, and panels to the minimum app version released in February 2026 before October 2026 to avoid ...

11 hours ago

Microsoft Power Platform governance and administration – Secure Dataverse record with column-based filtering

We are announcing the ability for admins to use filtered views to select and manage record-level access securely by defining security based on...

11 hours ago

Microsoft Teams: Impersonation Protection for Teams meetings

Impersonation Protection for Teams meetings helps users identify potentially deceptive participants and meeting organizers. When Teams detects...

2 days ago

Microsoft Copilot (Microsoft 365): Use Dataverse Business Skills in Sales Agent

Business Skills are natural language instructions authored and stored in Microsoft Dataverse that teach Sales Agent how work gets done within ...

2 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.