Microsoft Entra ID will enhance authentication security by enforcing a Content Security Policy that blocks external script injection, allowing only trusted Microsoft scripts. This rollout begins mid-October 2026, affecting browser-based sign-ins on login.microsoftonline.com, with no impact on Entra External ID tenants.
Introduction
As part of Microsoft’s Secure Future Initiative, we’re updating our Content Security Policy for the Microsoft Entra ID sign-in experience. This change adds an extra layer of protection by allowing only scripts from trusted Microsoft domains to run during authentication, blocking unauthorized or injected external code. This proactive measure helps safeguard users against threats like cross-site scripting (XSS), further strengthening security for your organization.
When this will happen
General Availability (Production/Worldwide only):
Periodic communications will be sent closer to release.
How this affects your organization
Who is affected:
What will happen:
What you can do to prepare
Learn more:
Compliance considerations
No compliance considerations identified; review as appropriate for your organization.