Microsoft Entra ID to block sign-in script injection
Microsoft will start blocking external script injection on Entra ID sign-in pages in mid-October 2026. The goal is to shut out cross-site scripting (XSS) and similar attacks that try to steal credentials during login.
Entra ID is Microsoft's identity and access management (IAM) service, which handles sign-ins for Microsoft 365 and other cloud apps. The company reminded customers of the change in a message center update published on Monday, according to BleepingComputer.
The plan is not new. Microsoft first announced it in November 2025, when it said it would protect Entra ID sign-ins against script injection. The enforcement phase now has a date.
Only Microsoft-hosted scripts allowed
The change relies on a stricter Content Security Policy (CSP). A CSP is a set of rules that tells the browser which sources it may load and run scripts from. Under the new policy, Entra ID sign-in pages will only run scripts served from trusted Microsoft content delivery network (CDN) domains. Code from anywhere else will be blocked.
Enforcement begins in mid-October and should be complete by late October 2026. Once the rollout finishes, all users should be covered against a range of sign-in risks. These include XSS attacks, in which attackers inject malicious code into a website to capture the credentials that users type in.
"Microsoft Entra ID will enhance sign-in security by enforcing a Content Security Policy blocking external script injection starting mid-October 2026," the company said. "This change helps protect users from threats such as cross-site scripting (XSS) by allowing only trusted Microsoft-hosted scripts to run during authentication and blocking unauthorized or externally injected code."
What admins need to check
The policy does not distinguish between malicious code and legitimate tools that also inject scripts into the login page. Browser extensions and other utilities that change the sign-in page will stop working there.
Microsoft advises enterprise customers to stop using such extensions and tools before enforcement begins. It also recommends testing sign-in scenarios ahead of the deadline to find any dependencies on code-injection tools and fix them.
Administrators can check for problems in the browser's developer console. If a script is blocked, the console shows a violation in red text, with details about which script was stopped.
The change will not lock anyone out. "Users will continue to be able to sign in even if unsupported script injection tools no longer function. This change is enabled by default as part of the service update and does not require tenant configuration," Microsoft said.
There is also a clear limit on what the policy covers. "Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected because CSP enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com," the company explained.
In practice, applications that authenticate through MSAL or API-based flows keep working as before. Only the browser-based sign-in page at login.microsoftonline.com gets the new restrictions.
Part of the Secure Future Initiative
The update falls under Microsoft's Secure Future Initiative (SFI). The company launched the program after Chinese hackers breached Exchange Online mailboxes belonging to dozens of organizations and hundreds of individuals worldwide in May and June 2023.
The CSP enforcement is one of several changes made under SFI. Microsoft has disabled all ActiveX controls in the Windows versions of Microsoft 365 and Office 2024 apps. It has also changed Microsoft 365 security defaults to block access to Office, SharePoint and OneDrive files over legacy authentication protocols.
Our Take
The change is small, but the target matters. The Entra ID sign-in page is where many organizations' users enter the passwords that protect email, documents and cloud workloads. Any code that runs on that page in the victim's browser can read what they type. Limiting that page to Microsoft-hosted scripts removes one route attackers could use to harvest credentials at the point of entry.
It also fits a pattern in Microsoft's SFI work: removing older or looser mechanisms by default rather than asking customers to opt in. Disabling ActiveX and blocking legacy authentication protocols followed the same logic. This suggests Microsoft is increasingly willing to break some third-party tooling in exchange for a smaller attack surface, and to give customers a deadline instead of a choice.
The main risk for admins is operational. Organizations that rely on browser extensions to modify the sign-in page, for example for branding, helpers or monitoring, may find those tools stop working without warning if nobody tests beforehand. Microsoft says sign-ins will still succeed, so the fallout should be limited to broken features rather than outages. Still, running through key sign-in flows with the developer console open before mid-October is a cheap precaution.
It is worth keeping in mind that the policy only covers browser-based logins. It does nothing about credentials that are already exposed elsewhere, such as the secrets leaked in public code repositories, or about users who hand over passwords on lookalike pages in targeted phishing campaigns. A hardened login page helps, but phishing-resistant authentication and credential hygiene remain the bigger levers.
Going forward, it is worth watching whether the rollout finishes on schedule by late October, and whether vendors of affected extensions adjust their products or drop support for Entra ID sign-in pages. It will also be interesting to see if Microsoft extends similar CSP enforcement to other authentication surfaces it controls.
