Review the update and plan any required actions before rollout.
Primary Audience
Why this score?
AT A GLANCE
END USERS
IT ADMINS
ROLLOUT TIMELINE
Mid–Late October 2026
📢 Official Microsoft Message Center Announcement
Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection
Message ID: MC1481309
[What and why]
As part of Microsoft’s Secure Future Initiative, we are strengthening the security of the Microsoft Entra ID sign-in experience by introducing additional Content Security Policy (CSP) protections. This change helps protect users from threats such as cross-site scripting (XSS) by allowing only trusted Microsoft-hosted scripts to run during authentication and blocking unauthorized or externally injected code.
This post is a reminder of our previous announcement (MC1191924), which communicated this upcoming security change and the actions organizations may need to take before rollout.
[Rollout schedule]
- General Availability (Worldwide): Beginning in mid-October 2026 and expected to complete by late October 2026
[Impact on your organization]
Who is affected
- Organizations whose users authenticate through Microsoft Entra ID sign-in pages hosted on login.microsoftonline.com
- Organizations using browser extensions, monitoring tools, customization tools, or other solutions that inject scripts into the sign-in experience
- Microsoft Entra External ID tenants are not affected
Platforms and services
- Microsoft Entra ID
- Web-based authentication experiences using login.microsoftonline.com
- Browser-based sign-in experiences across supported browsers
What will happen
- A new Content Security Policy (CSP) header will be added to Microsoft Entra ID sign-in pages.
- Scripts will be permitted only from trusted Microsoft content delivery network (CDN) domains.
- Inline script execution will be restricted to trusted Microsoft-authorized sources.
- Browser extensions and tools that inject scripts into Microsoft Entra ID sign-in pages may stop functioning.
- Users will continue to be able to sign in even if unsupported script injection tools no longer function.
- This change is enabled by default as part of the service update and does not require tenant configuration.
- Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected because CSP enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com.
[Action required and recommendations]
If your organization does not use tools or extensions that inject code into Microsoft Entra ID sign-in pages, no action is required.
If your organization uses tools that inject code into the sign-in experience:
- Review the CSP guidance and assess whether any tools, browser extensions, or custom solutions rely on script injection.
- Test affected authentication workflows ahead of rollout.
- Replace or update any solutions that depend on script injection into Microsoft Entra sign-in pages.
- Communicate potential impacts to help desk and identity administration teams.
- Update internal documentation if it references affected authentication customizations.
Learn more
- Content Security Policy (CSP) rollout in Microsoft Entra ID – Microsoft identity platform | Microsoft Learn
- CSP ⟶ script-src Guide
- CSP Nonce ⟶ Script & Style Attribute
- Enhance protection of Microsoft Entra ID authentication by blocking external script injection | Microsoft Community Hub
- Secure Future Initiative – Secure by Design | Microsoft
- why-xss-still-matters-msrcs-perspective-on-a-25-year-old-threat
[Compliance considerations]
No compliance considerations identified. Review as appropriate for your organization.
Source: Microsoft Message Center • Analysed by MWPro


