Microsoft to Block External Script Injection in Entra ID Sign-In
Microsoft is updating its Content Security Policy (CSP) for Entra ID, a popular sign-in service. The update will block external script injection during authentication, protecting users from common threats like cross-site scripting (XSS). Starting mid-to-late October 2026, only scripts from trusted Microsoft domains will run on the sign-in page. This change aims to strengthen security … Read more