By Sofia Ramirez
Publication Date: 2026-09-30 15:00:00
Microsoft will begin enforcing a Content Security Policy on Entra ID sign-ins in mid-October 2026. The policy is designed to block externally injected scripts on the login page.
The Brief
- Entra ID sign-in pages will allow only trusted Microsoft-hosted scripts to run during authentication, with enforcement starting in mid-October, per Microsoft.
- The rollout should end by late October 2026. Microsoft says it is on by default and needs no tenant setup.
- Sign-ins in a browser are in scope. Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected, Microsoft says.
- Enterprise customers should stop using browser extensions and tools that inject code or scripts into sign-in pages, according to Microsoft.
Entra ID sign-ins will accept only Microsoft-hosted scripts
Microsoft first revealed plans to secure Entra ID sign-ins from script injection attacks in a November 2025 announcement, according to BleepingComputer. The enforcement step…

