Microsoft to block Entra ID script injection attacks starting October

by · BleepingComputer

Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month.

The company first revealed plans to secure Entra ID sign-ins from script injection attacks in a November 2025 announcement.

According to a Monday message center update seen by BleepingComputer, Microsoft will begin enforcing additional Content Security Policy (CSP) defenses that will only allow scripts from trusted Microsoft content delivery network (CDN) domains during Entra ID sign-ins.

The rollout should end by late October 2026, after which all users will be protected from various sign-in security risks, including cross-site scripting attacks in which malicious code is injected into websites to steal credentials.

"Microsoft Entra ID will enhance sign-in security by enforcing a Content Security Policy blocking external script injection starting mid-October 2026," the company said. "This change helps protect users from threats such as cross-site scripting (XSS) by allowing only trusted Microsoft-hosted scripts to run during authentication and blocking unauthorized or externally injected code."

​Microsoft advised enterprise customers to stop using browser extensions and tools that inject code or scripts into sign-in pages before the new CSP changes take effect.

It also urged them to test sign-in scenarios before the next month's deadline to identify and address any dependency issues on code-injection tools. IT administrators can identify potential impact by reviewing sign-in flows in the browser developer console and looking for violations that appear in red text with details about the blocked scripts.

CSP policy violation (Microsoft)

​"Users will continue to be able to sign in even if unsupported script injection tools no longer function. This change is enabled by default as part of the service update and does not require tenant configuration," the company added.

"Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected because CSP enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com."

This change is part of Microsoft's Secure Future Initiative (SFI), announced after Chinese hackers breached the Exchange Online mailboxes of dozens of organizations and hundreds of individuals worldwide in May and June 2023.

As part of the same initiative, Microsoft also disabled all ActiveX controls in Windows versions of Microsoft 365 and Office 2024 apps, and it updated Microsoft 365 security defaults to block access to Office, SharePoint, and OneDrive files via legacy authentication protocols.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat