Changes › MC1481309

Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection

Published
28 Sep 2026
Last modified
28 Sep 2026 23:44 UTC
Act by
19 Oct 2026 (in 17 days)
Ends
16 Dec 2026
First archived
29 Sep 2026
Revisions
1
Tags
Feature updateUser impactAdmin impact

Full post

[What and why]

As part of Microsoft's Secure Future Initiative, we are strengthening the security of the Microsoft Entra ID sign-in experience by introducing additional Content Security Policy (CSP) protections. This change helps protect users from threats such as cross-site scripting (XSS) by allowing only trusted Microsoft-hosted scripts to run during authentication and blocking unauthorized or externally injected code.

This post is a reminder of our previous announcement (MC1191924), which communicated this upcoming security change and the actions organizations may need to take before rollout. 

[Rollout schedule]

  • General Availability (Worldwide): Beginning in mid-October 2026 and expected to complete by late October 2026

[Impact on your organization]

Who is affected

  • Organizations whose users authenticate through Microsoft Entra ID sign-in pages hosted on login.microsoftonline.com
  • Organizations using browser extensions, monitoring tools, customization tools, or other solutions that inject scripts into the sign-in experience
  • Microsoft Entra External ID tenants are not affected

Platforms and services

  • Microsoft Entra ID
  • Web-based authentication experiences using login.microsoftonline.com
  • Browser-based sign-in experiences across supported browsers

What will happen

  • A new Content Security Policy (CSP) header will be added to Microsoft Entra ID sign-in pages.
  • Scripts will be permitted only from trusted Microsoft content delivery network (CDN) domains.
  • Inline script execution will be restricted to trusted Microsoft-authorized sources.
  • Browser extensions and tools that inject scripts into Microsoft Entra ID sign-in pages may stop functioning.
  • Users will continue to be able to sign in even if unsupported script injection tools no longer function.
  • This change is enabled by default as part of the service update and does not require tenant configuration.
  • Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected because CSP enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com.

[Action required and recommendations]

If your organization does not use tools or extensions that inject code into Microsoft Entra ID sign-in pages, no action is required.

If your organization uses tools that inject code into the sign-in experience:

  • Review the CSP guidance and assess whether any tools, browser extensions, or custom solutions rely on script injection.
  • Test affected authentication workflows ahead of rollout.
  • Replace or update any solutions that depend on script injection into Microsoft Entra sign-in pages.
  • Communicate potential impacts to help desk and identity administration teams.
  • Update internal documentation if it references affected authentication customizations.

Learn more

[Compliance considerations]

No compliance considerations identified. Review as appropriate for your organization.

Related messages

Discussion

No messages yet — start the thread.

Sign in with your email to join the discussion — we send a one-time link, no password.

© Microsoft — archived from the Microsoft 365 Message Center. Content notice