Loading...

Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection

Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection

Microsoft Entra ID will enhance sign-in security by enforcing a Content Security Policy blocking external script injection starting mid-October 2026. Only trusted Microsoft scripts will run, affecting organizations using script-injecting tools on login.microsoftonline.com. No action needed if such tools aren’t used. As part of Microsoft’s Secure Future Initiative, we are strengthening the security of the Microsoft Entra ID sign-in experience by introducing additional Content Security Policy (CSP) protections. This change helps protect users from threats such as cross-site scripting (XSS) by allowing only trusted Microsoft-hosted scripts to run during authentication and blocking unauthorized or externally injected code. This post is a reminder of our previous announcement (MC1191924), which communicated this upcoming security change and the actions organizations may need to take before rollout.  Rollout schedule General Availability (Worldwide): Beginning in mid-October 2026 and expected to complete by late October 2026 Impact on your organization Who is affected Organizations whose users authenticate through Microsoft Entra ID sign-in pages hosted on login.microsoftonline.com Organizations using browser extensions, monitoring tools, customization tools, or other solutions that inject scripts into the sign-in experience Microsoft Entra External ID tenants are not affected Platforms and services Microsoft Entra ID Web-based authentication experiences using login.microsoftonline.com Browser-based sign-in experiences across supported browsers What will happen A new Content Security Policy (CSP) header will be added to Microsoft Entra ID sign-in pages. Scripts will be permitted only from trusted Microsoft content delivery network (CDN) domains. Inline script execution will be restricted to trusted Microsoft-authorized sources. Browser extensions and tools that inject scripts into Microsoft Entra ID sign-in pages may stop functioning. Users will continue to be able to sign in even if unsupported script injection tools no longer function. This change is enabled by default as part of the service update and does not require tenant configuration. Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected because CSP enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com. Action required and recommendations If your organization does not use tools or extensions that inject code into Microsoft Entra ID sign-in pages, no action is required. If your organization uses tools […]

The post Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.