Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update
Beginning in a year, Microsoft intends to strengthen the security of Entra ID authentication by preventing unwanted script injection attacks.
By limiting the execution of scripts from trusted Microsoft domains, the updated Content Security Policy (CSP) seeks to improve the Entra ID sign-in experience at "login.microsoftonline[.]com".
According to the Windows manufacturer, this update improves security and adds an additional layer of protection by preventing unauthorized or injected code from running during the sign-in process and only permitting scripts from trusted Microsoft domains to run during authentication.
In particular, it only permits inline script execution from a Microsoft trusted source and script downloads from Microsoft trusted CDN domains read more about Microsoft ...

