Skip to content
Microsoft Enhances Entra ID Security Against Script Injection Attacks

Microsoft Enhances Entra ID Security Against Script Injection Attacks

First seen 30 Sep 2026, 21:37 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 22:31 UTC
  • •Microsoft will enforce CSP checks on Entra ID sign-ins starting mid-October 2026.
  • •The changes aim to block external script injections and enhance security against XSS attacks.
  • •Enterprise customers are advised to stop using code-injection tools before the enforcement date.

Starting mid-October 2026, Microsoft will enforce stricter Content Security Policy (CSP) checks on Entra ID sign-ins to block external script injections. This initiative aims to protect users from cross-site scripting (XSS) and other sign-in attacks by allowing only scripts from trusted Microsoft CDN domains. The changes are part of Microsoft's Secure Future Initiative, which was announced following a significant breach in 2023. Enterprise customers are advised to discontinue the use of browser extensions that inject scripts into sign-in pages before the CSP enforcement takes effect. IT administrators should test their sign-in scenarios to identify potential issues with code-injection tools. The rollout is automatic and requires no tenant configuration, ensuring all users are protected without additional setup. Microsoft emphasized that users can still sign in even if unsupported tools are disabled.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-11-01
Microsoft announces plans for CSP enforcement
Microsoft revealed intentions to enhance security for Entra ID against script injection attacks.
BleepingComputer
2026-09-30
CSP enforcement details published
Microsoft confirmed the automatic enforcement of CSP checks to begin mid-October 2026, enhancing sign-in security.
Feeds.4Sysops

More articles in this cluster (2)

Common questions

When will the CSP enforcement take effect?
The enforcement will begin in mid-October 2026.
What should enterprise customers do before the changes?
They should stop using browser extensions that inject scripts into sign-in pages and test their sign-in scenarios.
Will users still be able to sign in after the changes?
Yes, users can still sign in even if unsupported script injection tools are disabled.