MC1481309: Microsoft Entra ID Strengthens Sign-In Security by Blocking External Script Injection

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
59
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
▶ What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Tenant AdminsMicrosoft 365 AdminsSecurity TeamsCompliance TeamsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
This update reinforces Microsoft Entra ID sign-in security by blocking external script injection via a new Content Security Policy. It will mainly impact organisations running browser extensions or monitoring tools that inject scripts into login.microsoftonline.com. Admins must review authentication workflows, test affected sign-in flows and update or remove unsupported tools before rollout in October 2026. The change improves sign-in security, but some custom tooling may stop working, requiring moderate planning and communication.
70
🛡️ Admin Impact
35
👥 User Impact
60
⚡ Urgency
55
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Microsoft is adding stricter script controls to Entra ID sign-in pages to block external code injection and improve security.
👥

END USERS

No major end-user change expected.
🛡️

IT ADMINS

Check if any tools or extensions inject scripts into Entra sign-in pages and test affected workflows before rollout.
📅

ROLLOUT TIMELINE

Upcoming:
Mid–Late October 2026

📢 Official Microsoft Message Center Announcement


Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection
Message ID: MC1481309

[What and why]

As part of Microsoft’s Secure Future Initiative, we are strengthening the security of the Microsoft Entra ID sign-in experience by introducing additional Content Security Policy (CSP) protections. This change helps protect users from threats such as cross-site scripting (XSS) by allowing only trusted Microsoft-hosted scripts to run during authentication and blocking unauthorized or externally injected code.

This post is a reminder of our previous announcement (MC1191924), which communicated this upcoming security change and the actions organizations may need to take before rollout. 

[Rollout schedule]

  • General Availability (Worldwide): Beginning in mid-October 2026 and expected to complete by late October 2026

[Impact on your organization]

Who is affected

  • Organizations whose users authenticate through Microsoft Entra ID sign-in pages hosted on login.microsoftonline.com
  • Organizations using browser extensions, monitoring tools, customization tools, or other solutions that inject scripts into the sign-in experience
  • Microsoft Entra External ID tenants are not affected

Platforms and services

  • Microsoft Entra ID
  • Web-based authentication experiences using login.microsoftonline.com
  • Browser-based sign-in experiences across supported browsers

What will happen

  • A new Content Security Policy (CSP) header will be added to Microsoft Entra ID sign-in pages.
  • Scripts will be permitted only from trusted Microsoft content delivery network (CDN) domains.
  • Inline script execution will be restricted to trusted Microsoft-authorized sources.
  • Browser extensions and tools that inject scripts into Microsoft Entra ID sign-in pages may stop functioning.
  • Users will continue to be able to sign in even if unsupported script injection tools no longer function.
  • This change is enabled by default as part of the service update and does not require tenant configuration.
  • Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected because CSP enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com.

[Action required and recommendations]

If your organization does not use tools or extensions that inject code into Microsoft Entra ID sign-in pages, no action is required.

If your organization uses tools that inject code into the sign-in experience:

  • Review the CSP guidance and assess whether any tools, browser extensions, or custom solutions rely on script injection.
  • Test affected authentication workflows ahead of rollout.
  • Replace or update any solutions that depend on script injection into Microsoft Entra sign-in pages.
  • Communicate potential impacts to help desk and identity administration teams.
  • Update internal documentation if it references affected authentication customizations.

Learn more

[Compliance considerations]

No compliance considerations identified. Review as appropriate for your organization.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update