Microsoft to enforce script injection protections in Entra ID
Starting mid-October, Microsoft will block external scripts from running on Entra ID login pages, limiting scripts to those hosted by Microsoft. This is meant to reduce risks like cross-site scripting attacks that steal user credentials. Enterprise customers using browser extensions or tools that inject scripts into the sign-in flow will need to stop before the change. Enforcement is automatic and doesn’t require any setup.
- Microsoft enforcing Content Security Policy for Entra ID logins
- Only Microsoft-hosted scripts allowed on sign-in pages
- Change rolls out automatically mid-October, no admin action required
- Sign-in flows that depend on script injection tools may break
- APIs and Microsoft Authentication Library not affected
Sources covering this
In this story
More in Cybersecurity
AI accelerates discovery of high-risk software vulnerabilities
Google’s Threat Intelligence Group reported that monthly vulnerability disclosures have doubled this year, increasing from 5,045 in…
OpenAI disrupts novel AI distillation attack it links to China
OpenAI announced it has stopped a coordinated attempt to extract and distill reasoning capabilities from its AI systems, attributing a…
Cisco SD-WAN Manager vulnerability actively exploited
Cisco has disclosed a critical security vulnerability (CVE-2026-76504) in Catalyst SD-WAN Manager that is being exploited by attackers.
Unpatched Zimbra flaw exploited to steal emails and credentials
A critical security vulnerability in Zimbra Collaboration Suite has been exploited by attackers to access emails and authentication data…