MC1481309 - Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection
Microsoft 365 Message Center announcement MC1481309.
MS Message Center's Summary
Microsoft is improving sign in security by enforcing a Content Security Policy on login.microsoftonline.com starting in October 2026. This change blocks external and unauthorized script injection to protect against cross site scripting threats. Organisations must audit their browser extensions, monitoring tools, and custom solutions that inject code into authentication pages before rollout to prevent unexpected failures.
- Administrator impact
- Review and test any internal tools, browser extensions, or custom solutions that inject scripts into the sign in experience before mid October 2026.
- End user impact
- Users relying on unauthorised script injection tools during authentication may see those tools stop working, though standard sign in will continue to function.
- Importance
- 6/10: This security update modifies sign in behaviour and can break third party or custom tools that inject scripts into authentication pages.
Content Security Policy rollout in Microsoft Entra ID
Enhance protection of Microsoft Entra ID authentication by blocking external script injection
Microsoft Summary
Microsoft Entra ID will enhance sign-in security by enforcing a Content Security Policy blocking external script injection starting mid-October 2026. Only trusted Microsoft scripts will run, affecting organizations using script-injecting tools on login.microsoftonline.com. No action needed if such tools aren't used.
- Message Center ID
- MC1481309
- Category
- plan For Change
- Severity
- normal
- Services
- Microsoft Entra, Microsoft 365 suite
- Tags
- Feature update, User impact, Admin impact
- Published
- 2026-09-28
- Last updated
- 2026-09-28
- Expires
- 2026-12-16
- Action required by
- 2026-10-19
[What and why] As part of Microsoft's Secure Future Initiative, we are strengthening the security of the Microsoft Entra ID sign-in experience by introducing additional Content Security Policy (CSP) protections. This change helps protect users from threats such as cross-site scripting (XSS) by allowing only trusted Microsoft-hosted scripts to run during authentication and blocking unauthorized or externally injected code. This post is a reminder of our previous announcement (MC1191924), which communicated this upcoming security change and the actions organizations may need to take before rollout. [Rollout schedule] General Availability (Worldwide): Beginning in mid-October 2026 and expected to complete by late October 2026 [Impact on your organization] Who is affected Organizations whose users authenticate through Microsoft Entra ID sign-in pages hosted on login.microsoftonline.com Organizations using browser extensions, monitoring tools, customization tools, or other solutions that inject scripts into the sign-in experience Microsoft Entra External ID tenants are not affected Platforms and services Microsoft Entra ID Web-based authentication experiences using login.microsoftonline.com Browser-based sign-in experiences across supported browsers What will happen A new Content Security Policy (CSP) header will be added to Microsoft Entra ID sign-in pages. Scripts will be permitted only from trusted Microsoft content delivery network (CDN) domains. Inline script execution will be restricted to trusted Microsoft-authorized sources. Browser extensions and tools that inject scripts into Microsoft Entra ID sign-in pages may stop functioning. Users will continue to be able to sign in even if unsupported script injection tools no longer function. This change is enabled by default as part of the service update and does not require tenant configuration. Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected because CSP enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com. [Action required and recommendations] If your organization does not use tools or extensions that inject code into Microsoft Entra ID sign-in pages, no action is required. If your organization uses tools that inject code into the sign-in experience: Review the CSP guidance and assess whether any tools, browser extensions, or custom solutions rely on script injection. Test affected authentication workflows ahead of rollout. Replace or update any solutions that depend on script injection into Microsoft Entra sign-in pages. Communicate potential impacts to help desk and identity administration teams. Update internal documentation if it references affected authentication customizations. Learn more Content Security Policy (CSP) rollout in Microsoft Entra ID - Microsoft identity platform | Microsoft Learn CSP ⟶ script-src Guide CSP Nonce ⟶ Script & Style Attribute Enhance protection of Microsoft Entra ID authentication by blocking external script injection | Microsoft Community Hub Secure Future Initiative – Secure by Design | Microsoft why-xss-still-matters-msrcs-perspective-on-a-25-year-old-threat [Compliance considerations] No compliance considerations identified. Review as appropriate for your organization.