Microsoft Boosts Entra ID Security with Script Injection Attack Protections
Microsoft is bolstering the security of its Entra ID authentication system by implementing additional Content Security Policy (CSP) defenses to block script injection attacks. This change, part of Microsoft's Secure Future Initiative (SFI), aims to protect users from cross-site scripting threats that can steal credentials.
The company first announced plans to secure Entra ID sign-ins in November 2025 and will begin enforcing the new CSP policy starting mid-October 2026. The rollout should be completed by late October, at which point all users will be protected from various sign-in security risks.
Microsoft advises enterprise customers to stop using browser extensions and tools that inject code or scripts into sign-in pages before the new CSP changes take effect. IT administrators can identify potential impact by reviewing sign-in flows in the browser developer console for violations, which will appear in red text with details about the blocked scripts.