Microsoft Entra ID adds CSP enforcement to block script injection during sign-ins
Security Tool/Service
Summary
Hide ▲
Show ▼
Microsoft Entra ID is rolling out Content Security Policy (CSP) enforcement for browser-based sign-ins, blocking external script injection and reducing XSS-driven credential theft risk. The change applies to login.microsoftonline.com and limits authentication pages to trusted Microsoft-hosted scripts. Microsoft says the rollout starts in mid-October 2026 and finishes by late October 2026. Enterprises using browser extensions or tools that inject code into sign-in pages may need to test for blocked-script violations before the deadline.
Related Happenings
TrustSink rogue external MFA provider attack against Microsoft Entra
Technical Analysis
H score30
First: 23.09.2026 00:45
Last: 23.09.2026 00:45
Sources 1
About this happening:
Researchers demonstrated TrustSink, a post-compromise technique that abuses Microsoft Entra external MFA providers to capture passwords during legitimate sign-ins, creatin...
TrustSink rogue external MFA provider attack against Microsoft Entra
Technical AnalysisAbout this happening: Researchers demonstrated TrustSink, a post-compromise technique that abuses Microsoft Entra external MFA providers to capture passwords during legitimate sign-ins, creatin...
Windows 11 KB5124008 Active Directory domain trust breakage
Service Disruption
H score0
First: 16.09.2026 23:39
Last: 16.09.2026 23:39
Sources 1
About this happening:
The Windows 11 KB5124008 security update is breaking Active Directory domain trust on some enterprise systems, preventing valid users from signing in after reboot. Microso...
Windows 11 KB5124008 Active Directory domain trust breakage
Service DisruptionAbout this happening: The Windows 11 KB5124008 security update is breaking Active Directory domain trust on some enterprise systems, preventing valid users from signing in after reboot. Microso...
Latest development: 17.09.2026 11:24
Microsoft shared a temporary workaround for Windows 11 systems where the September 2026 security updates trigger Machine Identity Isolation enforcement and break domain trust and valid credential sign-ins on enterprise devices. Admins should disable Machine Identity Isolation using the same method used to enable it, restart the device, and reset the secure channel; Microsoft also says the feature is only supported in environments connected to Windows Server 2025 Domain Functional Level (DFL) and above.
Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836)
Vulnerability
H score49
First: 21.08.2026 09:06
Last: 21.08.2026 09:06
Sources 1
About this happening:
Microsoft Entra ID is facing CVE-2026-69836, a CVSS 10.0 remote-code-execution flaw that was exploited in the wild. The bug affects Microsoft’s cloud identity an...
Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836)
VulnerabilityAbout this happening: Microsoft Entra ID is facing CVE-2026-69836, a CVSS 10.0 remote-code-execution flaw that was exploited in the wild. The bug affects Microsoft’s cloud identity an...
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/Mitigation
H score31
First: 10.08.2026 15:25
Last: 10.08.2026 15:25
Sources 1
About this happening:
Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/MitigationAbout this happening: Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/Service
H score26
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/ServiceAbout this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Timeline
-
30.09.2026 16:37 2 articles · 1h ago
Microsoft Entra ID will enforce CSP to block external script injection
Mitigation Patch UpdateMicrosoft is telling customers that Entra ID browser-based sign-ins will be protected by Content Security Policy enforcement that allows only trusted Microsoft-hosted scripts from CDN domains, blocking external script injection and reducing cross-site scripting risk on login.microsoftonline.com. Enterprise customers are being advised to stop using browser extensions and other tools that inject code into sign-in pages and to test sign-in scenarios for blocked-script violations before the rollout completes, while Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected.
Show sources
- Microsoft to block Entra ID script injection attacks starting October — www.bleepingcomputer.com — 30.09.2026 16:37
- Microsoft to block Entra ID script injection attacks starting October — www.bleepingcomputer.com — 30.09.2026 16:37