---
title: "Microsoft Entra ID Will Block Injected Scripts at Sign-In"
date: 2026-09-30
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/09/microsoft-entra-id-will-block-injected-scripts.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# Microsoft Entra ID Will Block Injected Scripts at Sign-In

Microsoft will begin enforcing a Content Security Policy on Entra ID sign-ins in mid-October 2026. The policy is designed to block externally injected scripts on the login page.

## The Brief

- Entra ID sign-in pages will allow only trusted Microsoft-hosted scripts to run during authentication, with enforcement starting in mid-October, per Microsoft.
- The rollout should end by late October 2026. Microsoft says it is on by default and needs no tenant setup.
- Sign-ins in a browser are in scope. Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected, Microsoft says.
- Enterprise customers should stop using browser extensions and tools that inject code or scripts into sign-in pages, according to Microsoft.

## Entra ID sign-ins will accept only Microsoft-hosted scripts

Microsoft first revealed plans to secure Entra ID sign-ins from script injection attacks in a November 2025 announcement, according to BleepingComputer. The enforcement step will only allow scripts from trusted **Microsoft content delivery network (CDN)** domains during Entra ID sign-ins. That narrows the room for cross-site scripting (XSS), where malicious code is injected into websites to steal credentials.

Microsoft’s notice put the goal this way.

The change helps protect users from threats such as cross-site scripting (XSS), the company said. It works by allowing only trusted Microsoft-hosted scripts to run during authentication.

Microsoft urged customers to test sign-in scenarios in **[Entra ID](https://sqmagazine.co.uk/microsoft-entra-id-critical-tenant-flaw-patched/)** before enforcement starts, to find tools that depend on injected code. IT administrators can review sign-in flows in the browser developer console and look for violations that appear in red text. Those entries list the blocked scripts.

The company also addressed fallout for users. Users will continue to be able to sign in even if unsupported script injection tools no longer function. Microsoft said the change is enabled by default as part of the service update and does not require tenant configuration.

Scope is narrow. Microsoft said CSP enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com. Anything that rewrites that page in a browser is in play.

## The policy follows a pattern set by the Secure Future Initiative

The change is part of Microsoft’s Secure Future Initiative (SFI). SFI was announced after Chinese hackers breached the **Exchange Online mailboxes** of dozens of organizations. The breaches hit hundreds of individuals worldwide in **May and June 2023**. Under the same program, Microsoft disabled all ActiveX controls in Windows versions of Microsoft 365 and Office 2024 apps.

Microsoft also updated [Microsoft 365 security](https://sqmagazine.co.uk/microsoft-365-statistics/) defaults to block access to Office, SharePoint, and OneDrive files via legacy authentication protocols. Teams tracking [Cybersecurity Statistics](https://sqmagazine.co.uk/cybersecurity-statistics/) will recognize the shape: a legacy behavior is switched off by default.

**ActiveX**, legacy authentication and injected sign-in scripts share one logic: each removes by default a capability attackers could reach. A content security policy helps reduce risk rather than removing it. The next checkpoint arrives when Microsoft begins enforcing a Content Security Policy blocking external script injection starting mid-October 2026.