Home › Intelligence › Brief
BREACH BRIEF🟡 Medium Advisory

Microsoft Enforces CSP to Block External Script Injection in Entra ID Sign‑Ins

Microsoft will begin enforcing a strict Content Security Policy for Entra ID browser sign‑ins in October 2026, blocking any external scripts that could be used for XSS credential theft. The change creates a measurable control for organizations to demonstrate secure authentication and audit‑ready evidence.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 bleepingcomputer.com
🟡
Severity
Medium
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
2 recommended
📰
Source
bleepingcomputer.com

Microsoft Enforces CSP to Block External Script Injection in Entra ID Sign‑Ins

What Happened – Microsoft announced that, beginning mid‑October 2026, Entra ID will enforce a strict Content Security Policy (CSP) that only permits scripts from Microsoft‑owned CDN domains during browser‑based sign‑ins. The change blocks cross‑site scripting (XSS) attempts that inject malicious code into the login page.

Why It Matters for Trust & Control Assurance

  • This is a concrete example of a control‑objective—secure authentication and protection against client‑side code injection—that continuous‑control‑assurance programs are built to monitor and evidence.
  • Enforcing CSP provides a defensible audit trail (CSP‑violation logs) that demonstrates due‑diligence in protecting credential‑capture vectors.
  • Organizations that rely on Entra ID must validate that their own sign‑in flows (including custom extensions or legacy tools) remain functional, and capture evidence of compliance for frameworks such as NIST CSF 2.0.

Who Is Affected – Cloud‑based SaaS providers, enterprises using Microsoft Entra ID for identity‑as‑a‑service, and any organization that customizes browser‑based sign‑in experiences.

Recommended Actions

  • Review sign‑in pages in the browser developer console for CSP‑violation messages and remediate any third‑party script dependencies.
  • Disable or replace browser extensions and automation tools that inject code into the login page before the October deadline.
  • Capture CSP‑enforcement logs as part of your continuous control‑monitoring evidence set for audit readiness.
  • Update internal authentication policies to reference the new CSP requirement and communicate the change to end‑users.

Source: BleepingComputer

Technical Notes

  • The mitigation is applied via CSP headers that whitelist only Microsoft CDN domains for script sources.
  • Affected flows: browser‑based sign‑ins to login.microsoftonline.com. MSAL SDKs and API‑based authentication are unaffected.
  • No new CVE; this is a proactive hardening measure against XSS (client‑side script injection).

Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/microsoft-to-block-entra-id-script-injection-attacks-starting-october/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →