{"id":8794,"date":"2025-11-28T10:03:49","date_gmt":"2025-11-28T10:03:49","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/28\/microsoft-to-block-external-scripts-in-entra-id-logins-to-enhance-protections\/"},"modified":"2025-11-28T10:03:49","modified_gmt":"2025-11-28T10:03:49","slug":"microsoft-to-block-external-scripts-in-entra-id-logins-to-enhance-protections","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/28\/microsoft-to-block-external-scripts-in-entra-id-logins-to-enhance-protections\/","title":{"rendered":"Microsoft to Block External Scripts\u00a0 in Entra ID Logins to Enhance Protections"},"content":{"rendered":"<p>    Microsoft to Block External Scripts\u00a0 in Entra ID Logins to Enhance Protections<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Microsoft has announced a significant security upgrade to its Microsoft Entra ID authentication process, as part of the company\u2019s broader Secure Future Initiative.<\/p>\n<p>Microsoft is updating its Content Security Policy (CSP) to block the execution of external scripts during user sign-ins.<\/p>\n<p>This proactive measure is designed to shield organizations from evolving cyber threats, specifically <a href=\"https:\/\/cybersecuritynews.com\/okta-browser-plugin-xss-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">cross-site scripting<\/a> (XSS) attacks, where hackers attempt to inject malicious code into legitimate websites.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-what-is-changing\"><strong>What Is Changing?<\/strong><\/h2>\n<p>Currently, some browser extensions or tools may inject scripts into the sign-in page to modify its behavior or appearance. Starting in mid-to-late October 2026, Microsoft will enforce a stricter policy on\u00a0<em>login.microsoftonline.com<\/em>.<\/p>\n<p>Under this new rule, only scripts from trusted Microsoft domains will be allowed to run. Any unauthorized or external code attempting to execute during the login process will be automatically blocked.<\/p>\n<p>This change ensures that the sign-in experience remains a closed, secure environment, preventing attackers from exploiting vulnerabilities in third-party scripts.<\/p>\n<p>It is important to note that this update applies only to <a href=\"https:\/\/cybersecuritynews.com\/new-browser-based-rdp\/\" target=\"_blank\" rel=\"noreferrer noopener\">browser-based<\/a> sign-ins on the specific Microsoft login URL; Microsoft Entra External ID will not be affected.<\/p>\n<p><a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-entra-blog\/enhance-protection-of-microsoft-entra-id-authentication-by-blocking-external-scr\/4435200\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft<\/a> advises organisations to stop using any browser extensions or custom tools that modify the Entra ID sign-in page via script injection.<\/p>\n<p>While the login process itself will continue to function for users, any tools relying on injecting code will stop working once the update is enforced.<\/p>\n<p>To get ready, IT administrators should test their sign-in flows ahead of the 2026 deadline. You can identify potential issues now by opening the developer console in your browser while signing in.<\/p>\n<p>If your organization uses tools that violate the new policy, error messages will appear in red text in the console. <\/p>\n<p>Megna Kokkalera, Product Manager II at Microsoft, emphasized that this update adds a critical layer of defense for user identities.<\/p>\n<p>By eliminating the risk of unverified scripts, Microsoft ensures that organizations stay ahead of emerging <a href=\"https:\/\/cybersecuritynews.com\/must-know-security-threats-for-website-owners-the-top-5\/\" target=\"_blank\" rel=\"noreferrer noopener\">security threats <\/a>while maintaining a seamless, secure sign-in experience.<\/p>\n<p>Administrators are encouraged to assess their environments early to ensure a smooth transition when the policy goes into effect globally next year.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/microsoft-to-block-external-scripts-in-entra-id\/\">Microsoft to Block External Scripts\u00a0 in Entra ID Logins to Enhance Protections<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/microsoft-to-block-external-scripts-in-entra-id\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft to Block External Scripts\u00a0 in Entra ID Logins to Enhance Protections Microsoft has announced a significant security upgrade to its Microsoft Entra ID authentication process, as part of the company\u2019s broader Secure Future Initiative. Microsoft is updating its Content Security Policy (CSP) to block the execution of external scripts during user sign-ins. This proactive [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,158],"tags":[130],"class_list":["post-8794","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-microsoft","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8794"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8794"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8794\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8794"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8794"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8794"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}