Microsoft to block Entra ID script injection attacks starting October

A major boost in security protection for Microsoft’s Entra ID users is on the horizon. Starting next month, all Entra ID sign-ins will be shielded from external script injection attacks, thanks to a significant upgrade to the platform’s Content Security Policy (CSP) defenses.

For those unfamiliar with the technical details, let’s break it down: external script injection attacks occur when malicious code is injected into websites or apps during login attempts. This can happen through browser extensions, tools, or even compromised websites that inject unwanted scripts into users’ browsers. The malicious code then tries to steal sensitive information like login credentials. Entra ID sign-ins have been vulnerable to such attacks, but Microsoft’s new CSP defenses will change all that.

According to a recent update from Microsoft, the company will begin enforcing an additional layer of security during Entra ID sign-ins in late October 2026. This means that only trusted scripts from Microsoft’s own Content Delivery Network (CDN) domains will be allowed to run during authentication, blocking any unauthorized or externally injected code. The rollout is part of Microsoft’s Secure Future Initiative, launched after a high-profile breach involving Chinese hackers and Exchange Online mailboxes in 2023.

Microsoft has been urging enterprise customers to prepare for the change by stopping their use of browser extensions and tools that inject code into sign-in pages. They’re also advised to test their sign-in scenarios before the deadline to identify any potential issues caused by code-injection tools. IT administrators can review their sign-in flows in the browser developer console to spot any blocked scripts, which will appear in red text with details about the offending script.

The good news is that users won’t be impacted if they continue to use unsupported script injection tools – they’ll simply not work anymore. This change is part of a broader effort by Microsoft to strengthen its security posture and protect users from evolving threats. As part of the same initiative, the company has also disabled ActiveX controls in Windows versions of Microsoft 365 and Office 2024 apps.

What does this mean for you? If you’re an Entra ID user, make sure to take note of the upcoming change and plan accordingly. While it’s not necessary to panic, being aware of these changes will help you stay ahead of potential security risks. As always, keep your browser extensions and tools up-to-date, and be cautious when using sign-in pages that may inject unwanted scripts into your browser. By staying informed and vigilant, you’ll be well-prepared for the enhanced security protections coming to Entra ID sign-ins next month.


Source: Bleeping Computer — 2026-09-30