Skip to main content
CybersecurityHacking

Microsoft Bolsters Entra ID Defenses Against Script Injection Attacks

Modern tech company HQ with subtle login screen representation, conveying security and trust.

"Microsoft Entra ID will enhance sign-in security by enforcing a Content Security Policy blocking external script injection starting mid-October 2026," the company said.

Content Security Policy enforcement during Entra ID sign-ins

Microsoft will begin enforcing additional Content Security Policy (CSP) defenses for Entra ID sign-ins that limit which scripts can run during browser-based authentication. According to a message center update seen by BleepingComputer, the CSP enforcement will allow only scripts hosted on trusted Microsoft content delivery network (CDN) domains while users authenticate via login.microsoftonline.com.

What changes: allowed script sources and the risks they address

The change narrows the source list for executable scripts during sign-in, a move Microsoft frames as protection against external script injection and cross-site scripting (XSS) attacks that can be used to steal credentials. The company said the CSP will block "unauthorized or externally injected code" and permit "only trusted Microsoft-hosted scripts to run during authentication." By restricting script execution to Microsoft-hosted assets, the update aims to reduce a range of sign-in security risks tied to browser-based page manipulation.

Rollout schedule and default activation

Microsoft expects the rollout to begin in mid-October 2026 and to complete by late October 2026. The company emphasized that the change is enabled by default as part of a service update and does not require tenant configuration. Microsoft also reassured customers that "Users will continue to be able to sign in even if unsupported script injection tools no longer function."

Impact on browser script-injection tools, extensions, and other authentication flows

Microsoft advised enterprise customers to stop using browser extensions and tools that inject code or scripts into sign-in pages before the CSP changes take effect. The company urged testing of sign-in scenarios ahead of the mid-October deadline to identify dependencies on such tools. IT administrators can detect potential impacts by reviewing sign-in flows in the browser developer console and looking for violations that appear in red text containing details about blocked scripts.

Not all authentication paths are affected: Microsoft said the Microsoft Authentication Library (MSAL) and API-based authentication flows will not be impacted because the new CSP enforcement applies only to browser-based sign-in experiences that use login.microsoftonline.com.

What this means for enterprise customers, IT administrators, and adversaries

  • Enterprise customers: Microsoft explicitly told customers to stop relying on browser extensions and code-injection tools for sign-in pages and to test sign-in scenarios before the mid-October enforcement date.
  • IT administrators: Administrators are directed to use the browser developer console to spot CSP violations, which will show in red text with details about which scripts were blocked; they should validate that business-critical sign-in flows work without injected scripts.
  • Adversaries: Microsoft frames the change as part of defensive actions tied to past intrusions. The CSP enforcement is included in the Secure Future Initiative (SFI), which Microsoft announced after Chinese hackers breached Exchange Online mailboxes of dozens of organizations and hundreds of individuals worldwide in May and June 2023.

This CSP enforcement is one piece of Microsoft’s broader Secure Future Initiative. Alongside the Entra ID sign-in controls, Microsoft said it previously disabled all ActiveX controls in Windows versions of Microsoft 365 and Office 2024 apps and updated Microsoft 365 security defaults to block access to Office, SharePoint, and OneDrive files via legacy authentication protocols. Those steps, like the upcoming Entra ID CSP change, are presented as measures to reduce avenues of exploitation in browser and client authentication paths.

The change will be rolled out by late October 2026 and is enabled by default, so organizations should validate browser-based sign-ins now if they use tools that modify sign-in pages. Microsoft’s guidance makes clear that API and library-based authentication paths are out of scope, but for many enterprises the immediate task is operational: find injected scripts, test sign-in flows, and remove or replace any tooling that depends on external script injection before the mid-October start of enforcement.

Source: BleepingComputer — Microsoft to block Entra ID script injection attacks starting October