Microsoft will enforce a stricter Content Security Policy (CSP) for browser-based Microsoft Entra ID authentication beginning in mid-October 2026 and completing the rollout by late October. Sign-in pages at login.microsoftonline.com will permit scripts only from trusted Microsoft CDN domains, blocking unauthorized external code injection and reducing exposure to cross-site scripting (XSS) and credential-theft attacks.
The protection is enabled by default and requires no tenant-side configuration. Organizations should inventory browser extensions, custom tooling, and other integrations that inject scripts into Entra ID sign-in pages, remove or replace incompatible components, and test authentication workflows before enforcement; Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft will begin enforcing stricter Content Security Policy protections on browser-based Entra ID sign-in pages, allowing scripts only from trusted Microsoft CDN domains to block unauthorized script injection and reduce XSS credential-theft risk.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.