logo

Microsoft to Block External Scripts  in Entra ID Logins to Enhance Protections

ID: 17fac578-6490-5155-b500-f1028a16cc9f

STIX ID: report--17fac578-6490-5155-b500-f1028a16cc9f

Feed Name: cybersecurityNews.com

Date Published: 2025-11-28

Date Updated: 2026-04-21

Author: Abinaya

...
...

Microsoft announced, as part of its Secure Future Initiative, that starting mid-to-late October 2026 it will enforce a stricter Content Security Policy on login.microsoftonline.com to block all non-Microsoft scripts during browser-based sign-ins, mitigating cross-site scripting (XSS) risks; organizations should discontinue extensions or tools that inject code into the Entra ID sign-in page, test sign-in flows ahead of enforcement, and check browser console errors, noting that External ID is unaffected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.