Trusence Every claim has a source
Last updated 4 October 2026 Search Türkçe
← All stories
Security

Microsoft will block injected scripts in Entra ID sign-ins from mid-October 2026

The default change should cut browser sign-in risk, but companies that rely on code-injecting tools may need to adjust before the rollout ends in late October.

Microsoft says it will start tightening Entra ID sign-in protection in mid-October 2026 by enforcing Content Security Policy rules that block externally injected scripts and only permit trusted Microsoft-hosted code. The change is meant to reduce browser-based sign-in risks such as cross-site scripting, while Microsoft says MSAL and API-based authentication are not affected because the enforcement applies only to browser logins through login.microsoftonline.com. The company is telling enterprises to remove browser extensions and other tools that inject code into authentication pages, and to test their sign-in flows before the rollout so they can catch broken dependencies. Microsoft says the update is on by default and requires no tenant configuration, and that the rollout should finish by late October 2026.

Why it matters

This mostly affects enterprises that still depend on browser extensions or other tools that alter Microsoft sign-in pages. Those sign-ins will accept only trusted Microsoft-hosted scripts, so anything that injects code into the page may stop working when enforcement turns on. Microsoft says MSAL and API-based authentication are not affected, so the change is limited to browser logins.

Sources

  • BleepingComputer