API · SDK · runtime · authentication lifecycle intelligence

Last updated · 2 October 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-262 · Authentication & identity

Microsoft Entra begins browser sign-in CSP enforcement

Microsoft begins global Content Security Policy enforcement for browser sign-in at login.microsoftonline.com in mid-to-late October 2026.

Microsoft EntraCSPbrowser sign-inlogin.microsoftonline.comenforcement

Previous state

Injected or untrusted browser scripts could operate without the documented global sign-in CSP enforcement.

Current state

Microsoft applies CSP at login.microsoftonline.com to block untrusted and injected scripts; sign-in remains available but affected monitoring and injected-script workflows can break.

Who needs to care

Browser-based Entra sign-in experiences and third-party injected-script or monitoring workflows at login.microsoftonline.com.

What to do

Remove reliance on injected scripts and test browser sign-in workflows against CSP before the enforcement window.

What the source does not prove

The boundary covers browser sign-in at login.microsoftonline.com. External ID custom domains and MSAL/API authentication are outside the documented scope.

Lifecycle history

Dated event sequence

  1. CSP guidance documented

    Microsoft documented scope, exclusions and preparation guidance.

  2. Global rollout window

    Global enforcement begins in the mid-to-late October 2026 window.

Evidence ledger

First-party sources

  1. 01
    Microsoft Learn — Content Security Policy for Microsoft Entra browser sign-in

    Official Microsoft Entra browser-enforcement authority · 2025-11-25

    Open official source ↗