Microsoft to Block Script Injection on Entra ID Sign-In Pages

Organizations using authentication monitoring, customization, or browser-based security tools may need to review their deployments before Microsoft begins enforcing stricter security controls on Entra ID sign-in pages.

Cloud Computing

Key Takeaways:

  • Microsoft will enforce stricter CSP rules on Entra ID sign-in pages starting in October 2026.
  • Third-party tools that rely on script injection may stop functioning after the change.
  • Organizations should test authentication workflows and identify affected tools before enforcement begins.

Organizations increasingly rely on Microsoft Entra ID as the gateway to cloud services, but some security, monitoring, and customization tools inject scripts directly into Microsoft-hosted sign-in pages. These tools can add functionality, but script injection creates an additional attack surface that could be abused by malicious actors through techniques such as cross-site scripting (XSS) or unauthorized code execution during authentication.

To reduce this risk, Microsoft will begin enforcing stricter Content Security Policy (CSP) rules on Entra ID sign-in pages in October 2026. Once enabled, only Microsoft-approved scripts will be allowed to run. As a result, third-party browser extensions, monitoring products, and custom solutions that depend on injecting code into the authentication experience may stop working. Organizations that have built workflows around these tools could face operational disruptions if they are unprepared.

​”Users will continue to be able to sign in even if unsupported script injection tools no longer function. This change is enabled by default as part of the service update and does not require tenant configuration,” the company explained in the Microsoft 365 Admin Center. “Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected because CSP enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com.”

Organizations should review sign-in dependencies before October 2026

Microsoft recommends locking down the authentication experience by permitting scripts only from trusted Microsoft sources. This change is designed to strengthen protection against script-based attacks without requiring customer configuration.

Organizations should review any authentication-related tools, test login workflows before the rollout, and replace or update solutions that rely on script injection. Microsoft says standard browser sign-ins, as well as applications using MSAL or API-based authentication methods, will continue to work normally.

The enhanced security comes at the cost of reduced flexibility for organizations that have customized or monitored the sign-in experience through injected scripts. Microsoft gains a more secure and predictable authentication environment, but affected organizations may need to invest time and resources to redesign workflows, find alternative tools, and retrain support teams ahead of the enforcement deadline.