| MC1481309 | Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection |
|---|
| Classification | planForChange |
|---|---|
| Last Updated | 09/28/2026 23:44:16 |
| Start Time | 09/28/2026 23:43:47 |
| End Time | 12/16/2026 08:00:00 |
| Action Required By Date | 2026-10-19T07:00:00Z |
| Message Content |
[What and why] As part of Microsoft’s Secure Future Initiative, we are strengthening the security of the Microsoft Entra ID sign-in experience by introducing additional Content Security Policy (CSP) protections. This change helps protect users from threats such as cross-site scripting (XSS) by allowing only trusted Microsoft-hosted scripts to run during authentication and blocking unauthorized or externally injected code. This post is a reminder of our previous announcement (MC1191924), which communicated this upcoming security change and the actions organizations may need to take before rollout. [Rollout schedule]
[Impact on your organization] Who is affected
Platforms and services
What will happen
[Action required and recommendations] If your organization does not use tools or extensions that inject code into Microsoft Entra ID sign-in pages, no action is required. If your organization uses tools that inject code into the sign-in experience:
Learn more
[Compliance considerations] No compliance considerations identified. Review as appropriate for your organization. |
| Machine Translation |
[何となぜ] MicrosoftのSecure Future Initiativeの一環として、Microsoft Entra IDサインイン体験のセキュリティを強化し、追加のコンテンツセキュリティポリシー(CSP)保護を導入しています。この変更により、認証時に信頼できるMicrosoftホストスクリプトのみを実行させ、不正または外部注入されたコードをブロックすることで、クロスサイトスクリプト(XSS)などの脅威からユーザーを保護します。 この投稿は、前回の発表(MC1191924年)を思い出させるものです。そこでは、今後のセキュリティ変更と、展開前に組織が取るべき対応について伝えていました。 [展開スケジュール]
[組織への影響] 影響を受ける人物
ホームとサービス
何が起こるのか
[行動が必要と提言] もし組織がMicrosoft Entra IDのサインインページにコードを注入するツールや拡張機能を使用していない場合、何の対応も必要ありません。 もしあなたの組織がサインイン体験にコードを注入するツールを使用している場合:
詳しくはこちら
[コンプライアンスの考慮事項] コンプライアンス上の考慮事項は特定されていません。組織に応じた適切なレビューを行ってください。 |