What and why
As part of Microsoft's Secure Future Initiative, we are strengthening the security of the Microsoft Entra ID sign-in experience by introducing additional Content Security Policy (CSP) protections. This change helps protect users from threats such as cross-site scripting (XSS) by allowing only trusted Microsoft-hosted scripts to run during authentication and blocking unauthorized or externally injected code.
This post is a reminder of our previous announcement (MC1191924), which communicated this upcoming security change and the actions organizations may need to take before rollout.
Rollout schedule
- General Availability (Worldwide): Beginning in mid-October 2026 and expected to complete by late October 2026
Impact on your organization
Who is affected
- Organizations whose users authenticate through Microsoft Entra ID sign-in pages hosted on login.microsoftonline.com
- Organizations using browser extensions, monitoring tools, customization tools, or other solutions that inject scripts into the sign-in experience
- Microsoft Entra External ID tenants are not affected
Platforms and services
- Microsoft Entra ID
- Web-based authentication experiences using login.microsoftonline.com
- Browser-based sign-in experiences across supported browsers
What will happen
- A new Content Security Policy (CSP) header will be added to Microsoft Entra ID sign-in pages.
- Scripts will be permitted only from trusted Microsoft content delivery network (CDN) domains.
- Inline script execution will be restricted to trusted Microsoft-authorized sources.
- Browser extensions and tools that inject scripts into Microsoft Entra ID sign-in pages may stop functioning.
- Users will continue to be able to sign in even if unsupported script injection tools no longer function.
- This change is enabled by default as part of the service update and does not require tenant configuration.
- Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected because CSP enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com.
Action required and recommendations
If your organization does not use tools or extensions that inject code into Microsoft Entra ID sign-in pages, no action is required.
If your organization uses tools that inject code into the sign-in experience:
- Review the CSP guidance and assess whether any tools, browser extensions, or custom solutions rely on script injection.
- Test affected authentication workflows ahead of rollout.
- Replace or update any solutions that depend on script injection into Microsoft Entra sign-in pages.
- Communicate potential impacts to help desk and identity administration teams.
- Update internal documentation if it references affected authentication customizations.
Learn more
Compliance considerations
No compliance considerations identified. Review as appropriate for your organization.