Microsoft to block Entra ID script injection attacks starting October
Microsoft will enhance the security of its Entra ID authentication system starting mid-October 2026 by enforcing a Content Security Policy (CSP) that blocks external script injection attacks. This CSP will restrict scripts to only those hosted on trusted Microsoft CDN domains during browser-based sign-ins, mitigating risks such as cross-site scripting (XSS). The change is enabled by default and does not require tenant configuration. Microsoft advises customers to stop using browser extensions or tools that inject scripts into sign-in pages before the enforcement begins and to test sign-in flows for compatibility. API-based authentication flows and Microsoft Authentication Library (MSAL) are not affected by this change. This update is part of Microsoft's Secure Future Initiative, which aims to improve security following previous breaches.
AI Analysis
Technical Summary
Microsoft announced that starting mid-October 2026, Entra ID will enforce a stricter Content Security Policy during browser-based sign-ins to block external script injection attacks, including cross-site scripting. The CSP will allow only scripts from trusted Microsoft-hosted CDN domains, preventing unauthorized or malicious code execution during authentication. This enforcement applies only to browser sign-ins via login.microsoftonline.com and does not impact API-based authentication or MSAL. Enterprises are advised to discontinue use of any browser extensions or tools that inject scripts into sign-in pages and to test their sign-in scenarios for potential issues. The rollout is expected to complete by late October 2026. This measure is part of Microsoft's broader Secure Future Initiative, which includes other security enhancements following prior cyberattacks.
Potential Impact
The enforcement of the CSP will block external script injection attacks during Entra ID browser-based sign-ins, reducing the risk of credential theft and other security threats related to cross-site scripting. Users will still be able to sign in even if unsupported script injection tools stop functioning. API-based authentication flows remain unaffected. The update improves the overall security posture of Entra ID sign-ins by limiting script execution to trusted Microsoft sources.
Mitigation Recommendations
Microsoft has enabled this CSP enforcement by default as part of a service update; no tenant configuration is required. Customers should stop using browser extensions or tools that inject scripts into Entra ID sign-in pages before mid-October 2026 and test their sign-in flows using the browser developer console to identify any blocked scripts or violations. Since the change is already enabled by default, no additional action is required to receive the protection once the rollout completes.
Microsoft to block Entra ID script injection attacks starting October
Description
Microsoft will enhance the security of its Entra ID authentication system starting mid-October 2026 by enforcing a Content Security Policy (CSP) that blocks external script injection attacks. This CSP will restrict scripts to only those hosted on trusted Microsoft CDN domains during browser-based sign-ins, mitigating risks such as cross-site scripting (XSS). The change is enabled by default and does not require tenant configuration. Microsoft advises customers to stop using browser extensions or tools that inject scripts into sign-in pages before the enforcement begins and to test sign-in flows for compatibility. API-based authentication flows and Microsoft Authentication Library (MSAL) are not affected by this change. This update is part of Microsoft's Secure Future Initiative, which aims to improve security following previous breaches.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Microsoft announced that starting mid-October 2026, Entra ID will enforce a stricter Content Security Policy during browser-based sign-ins to block external script injection attacks, including cross-site scripting. The CSP will allow only scripts from trusted Microsoft-hosted CDN domains, preventing unauthorized or malicious code execution during authentication. This enforcement applies only to browser sign-ins via login.microsoftonline.com and does not impact API-based authentication or MSAL. Enterprises are advised to discontinue use of any browser extensions or tools that inject scripts into sign-in pages and to test their sign-in scenarios for potential issues. The rollout is expected to complete by late October 2026. This measure is part of Microsoft's broader Secure Future Initiative, which includes other security enhancements following prior cyberattacks.
Potential Impact
The enforcement of the CSP will block external script injection attacks during Entra ID browser-based sign-ins, reducing the risk of credential theft and other security threats related to cross-site scripting. Users will still be able to sign in even if unsupported script injection tools stop functioning. API-based authentication flows remain unaffected. The update improves the overall security posture of Entra ID sign-ins by limiting script execution to trusted Microsoft sources.
Defensive Guidance
Microsoft has enabled this CSP enforcement by default as part of a service update; no tenant configuration is required. Customers should stop using browser extensions or tools that inject scripts into Entra ID sign-in pages before mid-October 2026 and test their sign-in flows using the browser developer console to identify any blocked scripts or violations. Since the change is already enabled by default, no additional action is required to receive the protection once the rollout completes.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/microsoft-to-block-entra-id-script-injection-attacks-starting-october/","fetched":true,"fetchedAt":"2026-09-30T13:48:07.843Z","wordCount":714}
Threat ID: 6abd13172a4e24523d134ea3
Added to database: 09/30/2026, 13:48:07 UTC
Last enriched: 09/30/2026, 13:48:18 UTC
Last updated: 09/30/2026, 15:34:16 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.