Article Details

Scrape Timestamp (UTC): 2025-11-27 15:43:48.647

Source: https://thehackernews.com/2025/11/microsoft-to-block-unauthorized-scripts.html

Original Article Text

Click to Toggle View

Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update. Microsoft has announced plans to improve the security of Entra ID authentication by blocking unauthorized script injection attacks starting a year from now. The update to its Content Security Policy (CSP) aims to enhance the Entra ID sign-in experience at "login.microsoftonline[.]com" by only letting scripts from trusted Microsoft domains run. "This update strengthens security and adds an extra layer of protection by allowing only scripts from trusted Microsoft domains to run during authentication, blocking unauthorized or injected code from executing during the sign-in experience," the Windows maker said. Specifically, it only allows script downloads from Microsoft trusted CDN domains and inline script execution from a Microsoft trusted source. The updated policy is limited to browser-based sign-in experiences for URLs beginning with login.microsoftonline.com. Microsoft Entra External ID will not be affected. The change, which has been described as a proactive measure, is part of Microsoft's Secure Future Initiative (SFI) and is designed to safeguard users against cross-site scripting (XSS) attacks that make it possible to inject malicious code into websites. It's expected to be rolled out globally starting mid-to-late October 2026. Microsoft is urging organizations to test their sign-in flows thoroughly ahead of time to ensure that there are no issues and the sign-in experience has no friction. It's also advising customers to refrain from using browser extensions or tools that inject code or script into the Microsoft Entra sign-in experience. Those who follow this approach are recommended to switch to other tools that don't inject code. To identify any CSP violations, users can go through a sign-in flow with the dev console open and access the browser's Console tool within the developer tools to check for errors that say "Refused to load the script" for going against the "script-src" and "nonce" directives. Microsoft's SFI is a multi-year effort that seeks to put security above all else when designing new products and better prepare for the growing sophistication of cyber threats. It was first launched in November 2023 and expanded in May 2024 following a report from the U.S. Cyber Safety Review Board (CSRB), which concluded that the company's "security culture was inadequate and requires an overhaul." In its third progress report published this month, the tech giant said it has deployed over 50 new detections in its infrastructure to target high-priority tactics, techniques, and procedures, and that the adoption of phishing-resistant multi-factor authentication (MFA) for users and devices has hit 99.6%. Other notable changes enacted by Microsoft are as follows - "To align with Zero Trust principles, organizations should automate vulnerability detection, response, and remediation using integrated security tools and threat intelligence," Microsoft said. "Maintaining real-time visibility into security incidents across hybrid and cloud environments enables faster containment and recovery."

Daily Brief Summary

VULNERABILITIES // Microsoft Enhances Entra ID Security Against Script Injection Threats

Microsoft plans to block unauthorized script injections in Entra ID logins, aiming for a global rollout by October 2026, enhancing security against cross-site scripting (XSS) attacks.

The update to Content Security Policy (CSP) will allow only scripts from trusted Microsoft domains, safeguarding the login.microsoftonline.com experience from malicious code.

This proactive measure is part of Microsoft's Secure Future Initiative, which focuses on strengthening security in response to increasing cyber threats.

Organizations are advised to test their sign-in flows early to ensure seamless transitions and avoid disruptions when the new policy is enforced.

Microsoft cautions against using browser extensions that inject scripts into Entra sign-ins, recommending alternative tools that comply with the new security standards.

The Secure Future Initiative, launched in 2023, has already introduced over 50 new detections and achieved 99.6% adoption of phishing-resistant multi-factor authentication.

The initiative aligns with Zero Trust principles, advocating for automated vulnerability management and real-time security incident visibility across hybrid and cloud environments.