Microsoft to block Entra ID script injection attacks starting October

Microsoft to block Entra ID script injection attacks starting October
Microsoft says Entra ID will gain stronger protection against external script injection attacks, with new Content Security Policy rules starting in mid-October 2026. The update will block unauthorized scripts during browser-based sign-ins to reduce risks like XSS, and Microsoft advises customers to stop using code-injecting browser tools before the change takes effect. #EntraID #Microsoft #CSP #XSS

Keypoints

  • Microsoft will enforce new CSP defenses for Entra ID sign-ins.
  • Only scripts from trusted Microsoft CDN domains will be allowed.
  • The rollout is expected to finish by late October 2026.
  • The change is meant to block external script injection and XSS attacks.
  • Microsoft urges customers to stop using browser tools that inject code into sign-in pages.

Read More: https://www.bleepingcomputer.com/news/security/microsoft-to-block-entra-id-script-injection-attacks-starting-october/