HomeSecurityCSP Update 2026: Blocks unauthorized Scripts in Entra ID connections

CSP Update 2026: Blocks unauthorized Scripts in Entra ID connections

Microsoft has announced plans to improve the security of Entra ID, blocking unauthorized script injection attacks starting next year.

See also: Critical vulnerabilities in Cisco Unified Contact Center Express

Enter CSP ID

The Content Security Policy (CSP) update aims to improve the Entra ID login experience on “login.microsoftonline.com” by only allowing scripts from trusted Microsoft domains to run.

“This update enhances security and adds an extra layer of protection by only allowing scripts from trusted Microsoft domains to run during authentication, preventing the execution of unauthorized or injected code during the sign-in experience,” the company said.

Specifically, only scripts from trusted Microsoft CDN domains and embedded scripts from a trusted Microsoft source will be allowed to be downloaded. The updated policy is limited to browser-based sign-in experiences for URLs that start with login.microsoftonline.com. Microsoft Entra External ID will not be affected.

See also: Hackers target sites through outdated WordPress plugins

CSP Update 2026: Blocks unauthorized Scripts in Entra ID connections

The change, described as a precautionary measure, is part of Microsoft's Secure Future Initiative (SFI) and is designed to protect users from cross-site scripting (XSS) attacks that allow malicious code to be injected into web pages. It is expected to be rolled out globally in mid-to-late October 2026.

Microsoft encourages organizations to thoroughly test their sign-in flows in advance to ensure there are no issues and that the sign-in experience remains smooth.

The company also advises customers to avoid using browser extensions or tools that inject code or scripts into the Microsoft Entra sign-in experience. Those who take this approach are advised to switch to other tools that do not inject code.

See also: French antitrust authority rejects complaint against Microsoft

CSP Update 2026: Blocks unauthorized Scripts in Entra ID connections

To detect any CSP violations, users can go through a connection flow with the developer console open and check for errors that say “Refused to load script” for violations against the “script-src” and “nonce” directives.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS