Microsoft Entra ID hardens browser sign-ins with stricter Content Security Policy
Security Tool/Service
Summary
Hide ▲
Show ▼
Microsoft is tightening Entra ID browser sign-ins with a stronger Content Security Policy, reducing the risk of script injection and XSS-style credential theft during authentication. The change rolls out in mid-to-late October 2026 and applies only to browser-based logins at login.microsoftonline.com. It will allow scripts only from Microsoft-trusted domains and will not affect Microsoft Entra External ID. Organizations that rely on code-injection tools in sign-in pages will need to test and remove those dependencies before rollout.
Related Happenings
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/Service
H score26
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/ServiceAbout this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Microsoft Entra OAuth Client ID spoofing campaign
Campaign
H score58
First: 13.07.2026 16:00
Last: 13.07.2026 16:00
Sources 1
About this happening:
A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Microsoft Entra OAuth Client ID spoofing campaign
CampaignAbout this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Microsoft AiTM payroll pirate attack mitigation
Advisory/Mitigation
H score34
First: 10.04.2026 14:56
Last: 10.04.2026 14:56
Sources 1
About this happening:
Microsoft is urging defenders to harden Microsoft 365 and related HR workflows against AiTM-driven payroll theft by requiring phishing-resistant MFA, blocking...
Microsoft AiTM payroll pirate attack mitigation
Advisory/MitigationAbout this happening: Microsoft is urging defenders to harden Microsoft 365 and related HR workflows against AiTM-driven payroll theft by requiring phishing-resistant MFA, blocking...
Phishing-resistant authentication to block post-breach credential abuse and relay attacks
Defensive Guidance
H score41
First: 09.04.2026 17:02
Last: 09.04.2026 17:02
Sources 1
About this happening:
Phishing-resistant authentication is being emphasized as the control that can stop post-breach account takeover when exposed email records fuel credential stuffing, AiTM...
Phishing-resistant authentication to block post-breach credential abuse and relay attacks
Defensive GuidanceAbout this happening: Phishing-resistant authentication is being emphasized as the control that can stop post-breach account takeover when exposed email records fuel credential stuffing, AiTM...
Microsoft Windows 11 KB5079473 Microsoft account sign-in disruption
Service Disruption
H score0
First: 20.03.2026 09:33
Last: 20.03.2026 09:33
Sources 1
About this happening:
Microsoft's Windows 11 KB5079473 update is disrupting Microsoft account sign-ins across multiple apps, creating false no-internet errors and blocking normal access...
Microsoft Windows 11 KB5079473 Microsoft account sign-in disruption
Service DisruptionAbout this happening: Microsoft's Windows 11 KB5079473 update is disrupting Microsoft account sign-ins across multiple apps, creating false no-internet errors and blocking normal access...
Latest development: 23.03.2026 10:04
Microsoft started rolling out the KB5085516 optional out-of-band update to fix the Microsoft account sign-in bug that appears after KB5079473 on Windows 11 25H2 and 24H2. The update addresses the false no-internet sign-in failure affecting Microsoft Teams, OneDrive, Microsoft Edge, Microsoft 365 Copilot, Excel, and Word, and it is available through Windows Update or the Microsoft Update Catalog.
Timeline
-
26.11.2025 15:26 2 articles · 7mo ago
Microsoft plans Entra ID sign-in Content Security Policy hardening
Initial DisclosureMicrosoft plans to enhance Entra ID browser-based sign-ins with a strengthened Content Security Policy that will allow script downloads only from Microsoft-trusted content delivery network domains and inline script execution only from Microsoft-trusted sources during authentication. The change is scoped to URLs beginning with login.microsoftonline.com, does not affect Microsoft Entra External ID, and is intended to reduce external script injection and XSS-style credential theft risks; enterprise customers are advised to test sign-in scenarios and stop using browser extensions or tools that inject code or scripts into sign-in pages before the October 2026 rollout window.
Show sources
- Microsoft to secure Entra ID sign-ins from script injection attacks — www.bleepingcomputer.com — 26.11.2025 15:26
- Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update — thehackernews.com — 27.11.2025 17:37