Microsoft Entra External ID
Authentication

Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection

In brief

Microsoft Entra ID will enhance sign-in security by enforcing a Content Security Policy blocking external script injection starting mid-October 2026. Only trusted Microsoft scripts will run, affecting organizations using script-injecting tools on login.microsoftonline.com. No action needed if such tools aren't used.

Message Center announcement

What and why

As part of Microsoft's Secure Future Initiative, we are strengthening the security of the Microsoft Entra ID sign-in experience by introducing additional Content Security Policy (CSP) protections. This change helps protect users from threats such as cross-site scripting (XSS) by allowing only trusted Microsoft-hosted scripts to run during authentication and blocking unauthorized or externally injected code.

This post is a reminder of our previous announcement (MC1191924), which communicated this upcoming security change and the actions organizations may need to take before rollout. 

Rollout schedule

  • General Availability (Worldwide): Beginning in mid-October 2026 and expected to complete by late October 2026

Impact on your organization

Who is affected

  • Organizations whose users authenticate through Microsoft Entra ID sign-in pages hosted on login.microsoftonline.com
  • Organizations using browser extensions, monitoring tools, customization tools, or other solutions that inject scripts into the sign-in experience
  • Microsoft Entra External ID tenants are not affected

Platforms and services

  • Microsoft Entra ID
  • Web-based authentication experiences using login.microsoftonline.com
  • Browser-based sign-in experiences across supported browsers

What will happen

  • A new Content Security Policy (CSP) header will be added to Microsoft Entra ID sign-in pages.
  • Scripts will be permitted only from trusted Microsoft content delivery network (CDN) domains.
  • Inline script execution will be restricted to trusted Microsoft-authorized sources.
  • Browser extensions and tools that inject scripts into Microsoft Entra ID sign-in pages may stop functioning.
  • Users will continue to be able to sign in even if unsupported script injection tools no longer function.
  • This change is enabled by default as part of the service update and does not require tenant configuration.
  • Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected because CSP enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com.

Action required and recommendations

If your organization does not use tools or extensions that inject code into Microsoft Entra ID sign-in pages, no action is required.

If your organization uses tools that inject code into the sign-in experience:

  • Review the CSP guidance and assess whether any tools, browser extensions, or custom solutions rely on script injection.
  • Test affected authentication workflows ahead of rollout.
  • Replace or update any solutions that depend on script injection into Microsoft Entra sign-in pages.
  • Communicate potential impacts to help desk and identity administration teams.
  • Update internal documentation if it references affected authentication customizations.

Learn more

Compliance considerations

No compliance considerations identified. Review as appropriate for your organization.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…