Skip to content

Security2 publishers2 min readPublished

Entra ID sign-in pages will run only Microsoft-hosted scripts from mid-October

Microsoft will allow only scripts from its own CDN domains during Entra ID browser sign-ins under a Content Security Policy enforced from mid-October 2026. Browser extensions and tools that inject code into the sign-in page will stop working as the rollout completes in late October.

The Watch · Security desk

Illustration accompanying Entra ID sign-in pages will run only Microsoft-hosted scripts from mid-October
Generated illustration

What happened

  • The policy covers only browser-based sign-in at login.microsoftonline.com, so apps using the Microsoft Authentication Library or API-based flows are unaffected.
  • Enforcement is switched on by default as part of the service update, and Microsoft says tenants need no configuration to receive it.
  • Admins can spot affected tools by walking sign-in flows with the browser developer console open, where blocked scripts show up as red policy violations.
  • Microsoft first announced the plan in November 2025 and repeated the timing in a Monday message center update, according to BleepingComputer.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint An attacker who gets script onto the Entra sign-in page through an XSS flaw or an injecting extension loses that route to credentials once enforcement lands.
  • exposure Credential pages on attacker-controlled domains sit outside a policy scoped to login.microsoftonline.com, so lookalike phishing is unaffected by this change.
  • decision Teams that depend on a code-injecting extension must replace it or retire the workflow before mid-October, since the change arrives on by default without any tenant action.

Until enforcement starts, the policy does not block code injected into the Entra ID sign-in page [3]. Microsoft framed the change around cross-site scripting. "This change helps protect users from threats such as cross-site scripting (XSS) by allowing only trusted Microsoft-hosted scripts to run during authentication and blocking unauthorized or externally injected code," the company said [6]. BleepingComputer lists XSS among the sign-in risks the rollout addresses. It describes that attack as malicious code injected into a website to steal credentials [7].

Microsoft expects browser extensions and tools that inject code or scripts into sign-in pages to break. It told enterprise customers to stop using them before the policy takes effect [8]. BleepingComputer's account of the notice does not mention custom-branded sign-in pages. Breakage stops at the tool [11]. "Users will continue to be able to sign in even if unsupported script injection tools no longer function," Microsoft said [11].

For admins, the work before the deadline is inventory [9]. Microsoft urged customers to test sign-in scenarios before the deadline to find and fix any dependency on code-injection tools [9]. Customers have had about 11 months between the first announcement and the start of enforcement [1]. Monday's message center update, seen by BleepingComputer, reminded them that the protection starts next month [1].

The policy is part of Microsoft's Secure Future Initiative. Microsoft set up that program after Chinese hackers breached Exchange Online mailboxes at dozens of organizations and hundreds of individuals in May and June 2023 [14]. Under the same program, Microsoft disabled all ActiveX controls in Windows versions of Microsoft 365 and Office 2024 apps [15]. It also changed Microsoft 365 security defaults to block access to Office, SharePoint and OneDrive files over legacy authentication protocols [16].

What to watch

  • Whether Microsoft publishes a list of known-affected extensions, or a tenant-level exception, before enforcement starts in mid-October.
  • Compatibility notices from extension and tool vendors whose products write into login.microsoftonline.com as the rollout runs through late October.
  • Any move to apply the same script policy to Microsoft sign-in hosts beyond login.microsoftonline.com.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories