Microsoft Enforces Content Security Policy on Entra ID Sign-ins to Block Script Injection
Microsoft is implementing a Content Security Policy on Entra ID sign-ins to block externally injected scripts, which will start in mid-October 2026. The policy aims to reduce the risk of cross-site scripting (XSS) attacks by allowing only trusted Microsoft-hosted scripts to run during authentication.
This move is part of Microsoft's Secure Future Initiative (SFI), which was announced after a Chinese hacking incident in May and June 2023, where hundreds of individuals' Exchange Online mailboxes were breached. The SFI has already disabled ActiveX controls in Windows versions of Microsoft 365 and Office 2024 apps.
Entra ID sign-in pages will only allow trusted scripts from the Microsoft-hosted content delivery network (CDN) domains to run, reducing the risk of malicious code injection. This policy change is set to roll out by late October 2026 and is enabled by default as part of the service update.
Microsoft urges customers to test sign-in scenarios before enforcement starts and review sign-in flows in the browser developer console for any blocked scripts. Users will still be able to sign in even if unsupported script injection tools no longer function.