← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Microsoft to Block Entra ID Script Injection Attacks Starting October

🔄 Updated 2d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Entra ID will enforce Content Security Policy (CSP) from mid-October 2026.
  • CSP will block external script injection, allowing only trusted Microsoft CDN scripts.
  • The change protects against cross-site scripting (XSS) attacks.
  • Enterprise customers should test sign-in scenarios for compatibility.

Enhanced Entra ID Security

Microsoft announced that its Entra ID authentication system will implement enhanced protection against external script injection attacks. This security upgrade, initially revealed in November 2025, will begin enforcement in mid-October 2026.

The new measures involve Content Security Policy (CSP) defenses that will restrict script execution during Entra ID sign-ins to only those originating from trusted Microsoft content delivery network (CDN) domains. This aims to prevent malicious code injection.

Protection Against XSS Attacks

The primary goal of this change is to safeguard users from various sign-in security risks, including cross-site scripting (XSS) attacks. XSS involves injecting malicious code into websites to steal credentials or compromise user sessions. By limiting script sources, Microsoft intends to mitigate these threats.

The rollout is expected to conclude by late October 2026, at which point all Entra ID users will benefit from these new protections.

Guidance for Enterprise Customers

Microsoft advises enterprise customers to cease using browser extensions or tools that inject code or scripts into sign-in pages before the CSP changes take effect. The company recommends testing sign-in scenarios to identify and resolve any compatibility issues with existing code-injection tools.

IT administrators can monitor sign-in flows in browser developer consoles for CSP violations, which will appear as red text indicating blocked scripts. Microsoft states that users will still be able to sign in even if unsupported script injection tools cease to function, as the change is enabled by default and does not require tenant configuration.

Scope and Context

This security enhancement applies specifically to browser-based sign-in experiences using login.microsoftonline.com. Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected by this CSP enforcement.

The initiative is part of Microsoft's broader Secure Future Initiative (SFI), which was launched following a breach by Chinese hackers targeting Exchange Online mailboxes in May and June 2023. Other SFI actions include disabling ActiveX controls in Microsoft 365 and Office 2024 applications.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Microsoft will begin enforcing Content Security Policy (CSP) defenses in Entra ID starting mid-October 2026 to block external script injection attacks. This measure aims to protect users from cross-site scripting (XSS) by allowing only trusted Microsoft CDN scripts during sign-ins. The change is part of Microsoft's Secure Future Initiative to enhance security.