ST-2026-262 · Authentication & identity
Microsoft Entra begins browser sign-in CSP enforcement
Microsoft begins global Content Security Policy enforcement for browser sign-in at login.microsoftonline.com in mid-to-late October 2026.
Previous state
Injected or untrusted browser scripts could operate without the documented global sign-in CSP enforcement.
Current state
Microsoft applies CSP at login.microsoftonline.com to block untrusted and injected scripts; sign-in remains available but affected monitoring and injected-script workflows can break.
Affected users
Who needs to care
Browser-based Entra sign-in experiences and third-party injected-script or monitoring workflows at login.microsoftonline.com.
Required response
What to do
Remove reliance on injected scripts and test browser sign-in workflows against CSP before the enforcement window.
Evidence boundary
What the source does not prove
The boundary covers browser sign-in at login.microsoftonline.com. External ID custom domains and MSAL/API authentication are outside the documented scope.
Lifecycle history
Dated event sequence
- CSP guidance documented
Microsoft documented scope, exclusions and preparation guidance.
- Global rollout window
Global enforcement begins in the mid-to-late October 2026 window.
Evidence ledger
First-party sources
- 01Microsoft Learn — Content Security Policy for Microsoft Entra browser sign-in
Official Microsoft Entra browser-enforcement authority · 2025-11-25
Open official source ↗