Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Entra ID hardens browser sign-ins with stricter Content Security Policy

Security Tool/Service
First reported
Last updated
Happening score
H score 68
2 unique sources, 2 articles

Summary

Hide ▲

Microsoft is tightening Entra ID browser sign-ins with a stronger Content Security Policy, reducing the risk of script injection and XSS-style credential theft during authentication. The change rolls out in mid-to-late October 2026 and applies only to browser-based logins at login.microsoftonline.com. It will allow scripts only from Microsoft-trusted domains and will not affect Microsoft Entra External ID. Organizations that rely on code-injection tools in sign-in pages will need to test and remove those dependencies before rollout.

Related Happenings

Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA

Security Tool/Service
H score26 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...

Microsoft Entra OAuth Client ID spoofing campaign

Campaign
H score58 First: 13.07.2026 16:00 Last: 13.07.2026 16:00 Sources 1

About this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...

Microsoft AiTM payroll pirate attack mitigation

Advisory/Mitigation
H score34 First: 10.04.2026 14:56 Last: 10.04.2026 14:56 Sources 1

About this happening: Microsoft is urging defenders to harden Microsoft 365 and related HR workflows against AiTM-driven payroll theft by requiring phishing-resistant MFA, blocking...

Phishing-resistant authentication to block post-breach credential abuse and relay attacks

Defensive Guidance
H score41 First: 09.04.2026 17:02 Last: 09.04.2026 17:02 Sources 1

About this happening: Phishing-resistant authentication is being emphasized as the control that can stop post-breach account takeover when exposed email records fuel credential stuffing, AiTM...

Microsoft Windows 11 KB5079473 Microsoft account sign-in disruption

Service Disruption
H score0 First: 20.03.2026 09:33 Last: 20.03.2026 09:33 Sources 1

About this happening: Microsoft's Windows 11 KB5079473 update is disrupting Microsoft account sign-ins across multiple apps, creating false no-internet errors and blocking normal access...

Latest development: 23.03.2026 10:04

Microsoft started rolling out the KB5085516 optional out-of-band update to fix the Microsoft account sign-in bug that appears after KB5079473 on Windows 11 25H2 and 24H2. The update addresses the false no-internet sign-in failure affecting Microsoft Teams, OneDrive, Microsoft Edge, Microsoft 365 Copilot, Excel, and Word, and it is available through Windows Update or the Microsoft Update Catalog.

Timeline

  1. 26.11.2025 15:26 2 articles · 7mo ago

    Microsoft plans Entra ID sign-in Content Security Policy hardening

    Initial Disclosure

    Microsoft plans to enhance Entra ID browser-based sign-ins with a strengthened Content Security Policy that will allow script downloads only from Microsoft-trusted content delivery network domains and inline script execution only from Microsoft-trusted sources during authentication. The change is scoped to URLs beginning with login.microsoftonline.com, does not affect Microsoft Entra External ID, and is intended to reduce external script injection and XSS-style credential theft risks; enterprise customers are advised to test sign-in scenarios and stop using browser extensions or tools that inject code or scripts into sign-in pages before the October 2026 rollout window.

    Show sources