Microsoft to Block External Scripts in Entra ID Logins to Enhance Protections
ID: 17fac578-6490-5155-b500-f1028a16cc9f
STIX ID: report--17fac578-6490-5155-b500-f1028a16cc9f
Feed Name: cybersecurityNews.com
Microsoft announced, as part of its Secure Future Initiative, that starting mid-to-late October 2026 it will enforce a stricter Content Security Policy on login.microsoftonline.com to block all non-Microsoft scripts during browser-based sign-ins, mitigating cross-site scripting (XSS) risks; organizations should discontinue extensions or tools that inject code into the Entra ID sign-in page, test sign-in flows ahead of enforcement, and check browser console errors, noting that External ID is unaffected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
