GLOBAL SITUATIONMONITORING
466 published briefsUTCTue, Mar 24 20:23:07
Microsoft Entra ID
Information regarding Microsoft Entra ID and its security updates.
1 intelligence brief← Intelligence Hub
-

Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update
Microsoft is enhancing security for Entra ID authentication by blocking unauthorized script injection attacks, starting in late 2026. This move involves updating their Content Security Policy (CSP) for the “login.microsoftonline.com” sign-in experience, allowing only scripts from trusted Microsoft domains to execute, thereby preventing malicious code.