Microsoft announced that its Entra ID authentication system will implement enhanced protection against external script injection attacks. This security upgrade, initially revealed in November 2025, will begin enforcement in mid-October 2026.
The new measures involve Content Security Policy (CSP) defenses that will restrict script execution during Entra ID sign-ins to only those originating from trusted Microsoft content delivery network (CDN) domains. This aims to prevent malicious code injection.
The primary goal of this change is to safeguard users from various sign-in security risks, including cross-site scripting (XSS) attacks. XSS involves injecting malicious code into websites to steal credentials or compromise user sessions. By limiting script sources, Microsoft intends to mitigate these threats.
The rollout is expected to conclude by late October 2026, at which point all Entra ID users will benefit from these new protections.
Microsoft advises enterprise customers to cease using browser extensions or tools that inject code or scripts into sign-in pages before the CSP changes take effect. The company recommends testing sign-in scenarios to identify and resolve any compatibility issues with existing code-injection tools.
IT administrators can monitor sign-in flows in browser developer consoles for CSP violations, which will appear as red text indicating blocked scripts. Microsoft states that users will still be able to sign in even if unsupported script injection tools cease to function, as the change is enabled by default and does not require tenant configuration.
This security enhancement applies specifically to browser-based sign-in experiences using login.microsoftonline.com. Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected by this CSP enforcement.
The initiative is part of Microsoft's broader Secure Future Initiative (SFI), which was launched following a breach by Chinese hackers targeting Exchange Online mailboxes in May and June 2023. Other SFI actions include disabling ActiveX controls in Microsoft 365 and Office 2024 applications.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Microsoft will begin enforcing Content Security Policy (CSP) defenses in Entra ID starting mid-October 2026 to block external script injection attacks. This measure aims to protect users from cross-site scripting (XSS) by allowing only trusted Microsoft CDN scripts during sign-ins. The change is part of Microsoft's Secure Future Initiative to enhance security.