As of October this year, users of Microsoft’s Entra ID identity and access management solution will enjoy improved protection against a type of cyber threat known as script injection attacks. This means that malicious actors attempting to inject code into websites to steal credentials will be thwarted by enhanced security measures enforced by the company.
Microsoft’s Entra ID provides businesses with a secure way to manage user identities and access to their systems. However, like any complex system, it can have vulnerabilities if not properly configured or secured. Script injection attacks, also known as cross-site scripting (XSS), are a common type of cyber threat where malicious code is injected into websites through user input, allowing hackers to steal sensitive information such as login credentials.
To address this issue, Microsoft will begin enforcing additional Content Security Policy (CSP) defenses in the coming weeks. This new security measure will only allow scripts from trusted Microsoft content delivery network (CDN) domains during Entra ID sign-ins, effectively blocking external script injection attacks. The rollout is expected to be completed by late October 2026.
For enterprise customers, this means that they should take immediate action to ensure a smooth transition. Microsoft advises them to stop using browser extensions and tools that inject code or scripts into sign-in pages before the new CSP changes take effect. Additionally, IT administrators are urged to test sign-in scenarios before the next month’s deadline to identify and address any dependency issues on code-injection tools.
This change is part of Microsoft’s Secure Future Initiative (SFI), which aims to enhance the security posture of its products and services in response to emerging threats. The initiative was launched after a high-profile breach of Exchange Online mailboxes by Chinese hackers in 2023, highlighting the need for robust security measures to protect sensitive information.
The rollout of these enhanced CSP defenses will have a significant impact on the security landscape, providing businesses with an additional layer of protection against script injection attacks. By enforcing this new security measure, Microsoft is taking a proactive approach to safeguard its users and prevent potential data breaches.
As the cybersecurity landscape continues to evolve, it’s essential for businesses to stay vigilant and adapt to emerging threats. With this latest development, Microsoft is setting a high standard for security in the industry, demonstrating its commitment to protecting sensitive information from malicious actors.
Source: Bleeping Computer — 2026-09-30