Microsoft Enforces CSP to Block External Script Injection in Entra ID Sign‑Ins
What Happened – Microsoft announced that, beginning mid‑October 2026, Entra ID will enforce a strict Content Security Policy (CSP) that only permits scripts from Microsoft‑owned CDN domains during browser‑based sign‑ins. The change blocks cross‑site scripting (XSS) attempts that inject malicious code into the login page.
Why It Matters for Trust & Control Assurance
- This is a concrete example of a control‑objective—secure authentication and protection against client‑side code injection—that continuous‑control‑assurance programs are built to monitor and evidence.
- Enforcing CSP provides a defensible audit trail (CSP‑violation logs) that demonstrates due‑diligence in protecting credential‑capture vectors.
- Organizations that rely on Entra ID must validate that their own sign‑in flows (including custom extensions or legacy tools) remain functional, and capture evidence of compliance for frameworks such as NIST CSF 2.0.
Who Is Affected – Cloud‑based SaaS providers, enterprises using Microsoft Entra ID for identity‑as‑a‑service, and any organization that customizes browser‑based sign‑in experiences.
Recommended Actions
- Review sign‑in pages in the browser developer console for CSP‑violation messages and remediate any third‑party script dependencies.
- Disable or replace browser extensions and automation tools that inject code into the login page before the October deadline.
- Capture CSP‑enforcement logs as part of your continuous control‑monitoring evidence set for audit readiness.
- Update internal authentication policies to reference the new CSP requirement and communicate the change to end‑users.
Source: BleepingComputer
Technical Notes
- The mitigation is applied via CSP headers that whitelist only Microsoft CDN domains for script sources.
- Affected flows: browser‑based sign‑ins to
login.microsoftonline.com. MSAL SDKs and API‑based authentication are unaffected. - No new CVE; this is a proactive hardening measure against XSS (client‑side script injection).
Source: same as above