logo

Microsoft to secure Entra ID sign-ins from script injection attacks

ID: db61264b-76fb-595f-a486-05d61d1f5b93

STIX ID: report--db61264b-76fb-595f-a486-05d61d1f5b93

Feed Name: Bleeping Computer

Date Published: 2025-11-26

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft will harden Entra ID browser sign-ins in October 2026 by enforcing a stricter Content Security Policy that only permits scripts from Microsoft-trusted domains and blocks injected or unauthorized code, mitigating XSS and similar risks. Organizations are urged to test sign-in scenarios, review console CSP violations, and cease using extensions that inject scripts into login pages. This change is part of the Secure Future Initiative, which also includes blocking legacy auth to Microsoft 365 resources, disabling ActiveX in Office apps, and adding Teams screen-capture protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.