Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection
Microsoft Entra ID will enhance authentication security by enforcing a Content Security Policy that blocks external script injection, allowing only trusted Microsoft scripts. This rollout begins mid-October 2026, affecting browser-based sign-ins on login.microsoftonline.com, with no impact on Entra External ID tenants. Introduction As part of Microsoft’s Secure Future Initiative, we’re updating our Content Security Policy for the Microsoft Entra ID sign-in experience. This change adds an extra layer of protection by allowing only scripts from trusted Microsoft domains to run during authentication, blocking unauthorized or injected external code. This proactive measure helps safeguard users against threats like cross-site scripting (XSS), further strengthening security for your organization. When this will happen General Availability (Production/Worldwide only): Rollout begins mid-October 2026 Expected completion by late October 2026 Periodic communications will be sent closer to release. How this affects your organization Who is affected: Organizations using browser-based sign-in experiences on URLs starting with login.microsoftonline.com. No impact to Microsoft Entra External ID tenants. What will happen: A new Content Security Policy header will be added to Microsoft Entra sign-in pages. Scripts will only be allowed from Microsoft trusted CDN domains. Inline script execution will only be allowed from trusted Microsoft sources. Browser extensions or tools that inject code into the sign-in page will stop working, though users can still sign in. What you can do to prepare If you do not use tools or extensions that inject code into the sign-in experience, no action is required. If you do use such tools, switch to alternatives that don’t inject code. Test your sign-in flows thoroughly before rollout to identify and resolve any issues early. Testing instructions can be found on our CSP Guide for Microsoft Entra ID. Learn more: Compliance considerations No compliance considerations identified; review as appropriate for your organization. Content Security Policy Overview for Microsoft Entra ID Microsoft Entra ID Content Security Policy Public Blog Post on Techcommunity Microsoft Secure Future Initiative The CSP nonce guide | Content Security Policy (CSP) quick reference guide The CSP script-src directive guide | Content Security Policy (CSP) quick reference guide Why XSS still matters: MSRC’s perspective on […]
The post Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
External messaging limits for onmicrosoft.com-only organizations in Microsoft Teams
Microsoft Teams will impose outbound external messaging limits starting mid-September 2026 for organizations using only the default onmicrosof...
Microsoft Teams: Enable agents for existing applications in your organization
For third-party applications already being used in your organization, admins can now discover and enable the corresponding Teams agents from w...
Microsoft Viva: Campaigns Hub in Engage and Engage in Teams mobile
The Campaigns Hub in Viva Engage provides a centralized mobile destination where employees can discover and participate in organizational camp...
Planner: Conditional Coloring
Conditional Coloring highlight tasks based on selected criteria, making priorities, status, and important task details easier to spot. Product...
Outlook: Offline settings “Days of email to save” admin policy
Tenant admins will be able to define the default value for “Days of email to save” in Offline settings and designate whether end u...
Microsoft Copilot Studio: Agent Sharing amongst makers
Enables sharing of agents with other makers in the new GHCP harness. Makers can grant other makers Agent Viewer (view analytics/evaluations on...
OneDrive Photos on Windows: admin controls and policy support
OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...
Admin app retiring in Teams, Outlook and Microsoft365.com
The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...
Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting
Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...
Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices
The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...