Microsoft will begin enforcing new Content Security Policy defenses for Entra ID sign-ins in mid-October 2026, restricting authentication pages to scripts hosted on trusted Microsoft content delivery network domains. The rollout is expected to finish by late October, at which point all users will receive the added protection. The company first disclosed its intention to shield Entra ID sign-ins from script injection attacks in a November 2025 announcement.

According to a Monday message center update, the change is meant to defend against cross-site scripting and other sign-in risks in which malicious code is injected into websites to steal credentials. Microsoft said only trusted Microsoft-hosted scripts will be permitted to run during authentication, while unauthorized or externally injected code will be blocked. The company framed the step as an enhancement to sign-in security that is turned on by default as part of the service update.

Microsoft advised enterprise customers to stop using browser extensions and tools that inject code or scripts into sign-in pages before the policy takes effect. It also asked them to test sign-in scenarios ahead of next month's deadline so that any dependency on code-injection tools can be found and resolved. IT administrators can gauge the potential impact by reviewing sign-in flows in the browser developer console and looking for violations displayed in red text that describe the blocked scripts.

Microsoft said users will still be able to sign in even when unsupported script injection tools stop working. The change requires no tenant configuration, the company added. It also noted that the Microsoft Authentication Library and API-based authentication flows are unaffected, because enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com.

The move falls under Microsoft's Secure Future Initiative, which the company announced after Chinese hackers breached Exchange Online mailboxes at dozens of organizations and hundreds of individuals worldwide in May and June 2023. Under the same initiative, Microsoft disabled all ActiveX controls in Windows versions of Microsoft 365 and Office 2024 apps. It also updated Microsoft 365 security defaults to block access to Office, SharePoint and OneDrive files through legacy authentication protocols.

For US enterprises, the near-term effect is operational: administrators who rely on third-party extensions or scripts in their Entra ID sign-in flows have until the October enforcement window to verify those tools still work. Organizations that do not depend on injected code should see no required configuration work, according to Microsoft's guidance. The update applies to browser-based authentication only, leaving other authentication methods untouched.

More cybersecurity news from TechManNews.