Skip to content
TrustList
News

Entra ID sign-in pages will block injected scripts from mid-October: check extensions and tools by 19 October

Editorial

By TrustList Editorial

Microsoft will enforce a Content Security Policy on login.microsoftonline.com from mid-October 2026, allowing only Microsoft-hosted scripts. Browser extensions and tools that inject scripts into sign-in may stop working; act by 19 October.

About Entra ID sign-in pages will block injected scripts from mid-October: check extensions and tools by 19 October

Entra ID sign-in pages will block injected scripts from mid-October: check extensions and tools by 19 October

28 September 2026 — Microsoft told Microsoft 365 administrators on 28 September 2026 (Message Center post MC1481309, a reminder of an earlier notice) that it will add a Content Security Policy to the Microsoft Entra ID sign-in pages at login.microsoftonline.com. From then on only trusted, Microsoft-hosted scripts will run during sign-in; inline scripts are restricted and scripts from any other source are blocked. Microsoft gives 19 October 2026 as the date to act by.

When

The rollout starts in mid-October 2026 and is due to be complete, worldwide, by late October 2026. It is on by default and there is no tenant setting to postpone it.

What stops working

Users will still be able to sign in. What may break is anything that injects its own script into the sign-in page:

  • browser extensions that read, fill or change the Microsoft sign-in page by injecting a script into it;
  • monitoring, analytics or session-recording tools that add a script to the page;
  • custom or third-party solutions that change the sign-in experience by script rather than through Entra's supported company branding.

Microsoft Entra External ID tenants are not affected, and neither are sign-ins through MSAL or other API-based authentication flows.

Why Microsoft is doing it

Microsoft presents the change as protection against cross-site scripting on the sign-in page, where an injected script could read what a user types. It is part of Microsoft's Secure Future Initiative.

What to do

  • Find out which extensions and tools in your estate touch the Microsoft sign-in page. Browser-management policies usually show which extensions are allowed or forced on.
  • Test sign-in with those tools in a browser that enforces the new policy before mid-October; Microsoft's Learn page on the CSP rollout describes how.
  • Ask the vendors of any affected extension or monitoring product whether they already work without injecting scripts, and replace the ones that do not.
  • Tell the service desk and identity team, so that a broken extension in late October is not mistaken for a sign-in outage.

If no tool in your organisation injects scripts into sign-in, there is nothing to do.

Not yet independently verified. This rests only on Microsoft’s own Message Center post, read through a public archive because the admin centre requires sign-in; the Microsoft Learn rollout page it links to was not read separately, and no independent report was found. We will update this when it can be confirmed, and remove this note.

Sources

Categories & features