Microsoft to block script injection in Entra ID sign-ins from October
Microsoft will enforce a Content Security Policy for Entra ID sign-ins starting mid-October 2026, allowing only scripts from trusted Microsoft CDN domains. Admins are urged to drop code-injecting browser extensions and test sign-in flows before the deadline.
- CSP enforcement starts mid-October 2026 and finishes rolling out by late October
- Only scripts from trusted Microsoft CDN domains will run during sign-ins
- The change is on by default and needs no tenant configuration
- MSAL and API-based authentication flows are unaffected
Read next
Security