Microsoft Entra ID (Message Center / Bleeping 30 Sep): CSP blocks external script injection on sign-in from mid-October 2026
BleepingComputer (30 September 2026), citing a Microsoft Message Center update, reports that Microsoft Entra ID will enforce additional Content Security Policy (CSP) on browser sign-in experiences so only trusted Microsoft CDN-hosted scripts run during authentication, blocking external script injection / XSS-style credential theft on login.microsoftonline.com. Rollout begins mid-October 2026 and should complete by late October 2026; enabled by default, no tenant configuration required. MSAL and API-based auth flows are unaffected (CSP applies to browser sign-in only). Microsoft advises enterprises to stop relying on browser extensions/tools that inject code into Entra sign-in pages, and to test sign-in flows in browser developer tools for CSP violations (red console errors) before the deadline. Users can still sign in if unsupported injection tools break. Framed as part of Microsoft’s Secure Future Initiative. Wire-primary until a public Microsoft Learn / Message Center article URL is mirrored. Distinct from desk Entra SMS/voice/passkey and TrustSink EAM cards.
- Product
- Microsoft Entra ID browser sign-in (login.microsoftonline.com)
- Versions
- Service-side CSP enforcement mid–late October 2026 (default on; no tenant toggle). MSAL/API auth not affected.
- Exploited in Australia?
- unknown
- Patch to
- No CVE. Before mid-October 2026: inventory browser extensions / password managers / accessibility tools that inject into Entra sign-in; test critical SSO flows; expect CSP to block non-Microsoft CDN scripts. Prefer MSAL/native auth where possible. Monitor Message Center for the official MC article ID when published.
Primary: BleepingComputer — Microsoft to block Entra ID script injection from October (30 Sep 2026) · Vendor: Microsoft Entra (product); Message Center update cited by BleepingComputer · BleepingComputer (wire — Message Center not public HTML)
