Entra ID sign-in pages will block injected scripts from mid-October: check extensions and tools by 19 October
EditorialBy TrustList Editorial
Microsoft will enforce a Content Security Policy on login.microsoftonline.com from mid-October 2026, allowing only Microsoft-hosted scripts. Browser extensions and tools that inject scripts into sign-in may stop working; act by 19 October.
- Cybersecurity
- Cybersecurity Software
- Single Sign On
- Identity Management Software
About Entra ID sign-in pages will block injected scripts from mid-October: check extensions and tools by 19 October
Entra ID sign-in pages will block injected scripts from mid-October: check extensions and tools by 19 October
28 September 2026 — Microsoft told Microsoft 365 administrators on 28 September 2026 (Message Center post MC1481309, a reminder of an earlier notice) that it will add a Content Security Policy to the Microsoft Entra ID sign-in pages at login.microsoftonline.com. From then on only trusted, Microsoft-hosted scripts will run during sign-in; inline scripts are restricted and scripts from any other source are blocked. Microsoft gives 19 October 2026 as the date to act by.
When
The rollout starts in mid-October 2026 and is due to be complete, worldwide, by late October 2026. It is on by default and there is no tenant setting to postpone it.
What stops working
Users will still be able to sign in. What may break is anything that injects its own script into the sign-in page:
- browser extensions that read, fill or change the Microsoft sign-in page by injecting a script into it;
- monitoring, analytics or session-recording tools that add a script to the page;
- custom or third-party solutions that change the sign-in experience by script rather than through Entra's supported company branding.
Microsoft Entra External ID tenants are not affected, and neither are sign-ins through MSAL or other API-based authentication flows.
Why Microsoft is doing it
Microsoft presents the change as protection against cross-site scripting on the sign-in page, where an injected script could read what a user types. It is part of Microsoft's Secure Future Initiative.
What to do
- Find out which extensions and tools in your estate touch the Microsoft sign-in page. Browser-management policies usually show which extensions are allowed or forced on.
- Test sign-in with those tools in a browser that enforces the new policy before mid-October; Microsoft's Learn page on the CSP rollout describes how.
- Ask the vendors of any affected extension or monitoring product whether they already work without injecting scripts, and replace the ones that do not.
- Tell the service desk and identity team, so that a broken extension in late October is not mistaken for a sign-in outage.
If no tool in your organisation injects scripts into sign-in, there is nothing to do.
Not yet independently verified. This rests only on Microsoft’s own Message Center post, read through a public archive because the admin centre requires sign-in; the Microsoft Learn rollout page it links to was not read separately, and no independent report was found. We will update this when it can be confirmed, and remove this note.
Sources
Categories & features
- Cybersecurity
- Cybersecurity Software
- Single Sign On
- Identity Management Software
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.