Microsoft to enforce CSP for Entra ID sign-ins
🔒 Microsoft will begin enforcing stricter Content Security Policy (CSP) protections for Entra ID sign-ins starting mid-October 2026, allowing only scripts from trusted Microsoft CDN domains. The rollout will complete by late October 2026 and aims to block external script injection and cross-site scripting risks during browser-based authentication. Enterprise customers are urged to remove or test browser extensions and code-injection tools to avoid sign-in disruptions. MSAL and API-based flows are not affected because CSP applies only to browser-based sign-ins.
