Microsoft says Entra ID will gain stronger protection against external script injection attacks, with new Content Security Policy rules starting in mid-October 2026. The update will block unauthorized scripts during browser-based sign-ins to reduce risks like XSS, and Microsoft advises customers to stop using code-injecting browser tools before the change takes effect. #EntraID #Microsoft #CSP #XSS
Keypoints
- Microsoft will enforce new CSP defenses for Entra ID sign-ins.
- Only scripts from trusted Microsoft CDN domains will be allowed.
- The rollout is expected to finish by late October 2026.
- The change is meant to block external script injection and XSS attacks.
- Microsoft urges customers to stop using browser tools that inject code into sign-in pages.