SHD / MC Checker

MC1481309 | Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection



MC1481309 | Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection

Classification planForChange
Last Updated 09/28/2026 23:44:16
Start Time 09/28/2026 23:43:47
End Time 12/16/2026 08:00:00
Action Required By Date 2026-10-19T07:00:00Z
Message Content

[What and why]

As part of Microsoft’s Secure Future Initiative, we are strengthening the security of the Microsoft Entra ID sign-in experience by introducing additional Content Security Policy (CSP) protections. This change helps protect users from threats such as cross-site scripting (XSS) by allowing only trusted Microsoft-hosted scripts to run during authentication and blocking unauthorized or externally injected code.

This post is a reminder of our previous announcement (MC1191924), which communicated this upcoming security change and the actions organizations may need to take before rollout. 

[Rollout schedule]

  • General Availability (Worldwide): Beginning in mid-October 2026 and expected to complete by late October 2026

[Impact on your organization]

Who is affected

  • Organizations whose users authenticate through Microsoft Entra ID sign-in pages hosted on login.microsoftonline.com
  • Organizations using browser extensions, monitoring tools, customization tools, or other solutions that inject scripts into the sign-in experience
  • Microsoft Entra External ID tenants are not affected

Platforms and services

  • Microsoft Entra ID
  • Web-based authentication experiences using login.microsoftonline.com
  • Browser-based sign-in experiences across supported browsers

What will happen

  • A new Content Security Policy (CSP) header will be added to Microsoft Entra ID sign-in pages.
  • Scripts will be permitted only from trusted Microsoft content delivery network (CDN) domains.
  • Inline script execution will be restricted to trusted Microsoft-authorized sources.
  • Browser extensions and tools that inject scripts into Microsoft Entra ID sign-in pages may stop functioning.
  • Users will continue to be able to sign in even if unsupported script injection tools no longer function.
  • This change is enabled by default as part of the service update and does not require tenant configuration.
  • Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected because CSP enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com.

[Action required and recommendations]

If your organization does not use tools or extensions that inject code into Microsoft Entra ID sign-in pages, no action is required.

If your organization uses tools that inject code into the sign-in experience:

  • Review the CSP guidance and assess whether any tools, browser extensions, or custom solutions rely on script injection.
  • Test affected authentication workflows ahead of rollout.
  • Replace or update any solutions that depend on script injection into Microsoft Entra sign-in pages.
  • Communicate potential impacts to help desk and identity administration teams.
  • Update internal documentation if it references affected authentication customizations.

Learn more

[Compliance considerations]

No compliance considerations identified. Review as appropriate for your organization.

Machine Translation

[何となぜ]

MicrosoftのSecure Future Initiativeの一環として、Microsoft Entra IDサインイン体験のセキュリティを強化し、追加のコンテンツセキュリティポリシー(CSP)保護を導入しています。この変更により、認証時に信頼できるMicrosoftホストスクリプトのみを実行させ、不正または外部注入されたコードをブロックすることで、クロスサイトスクリプト(XSS)などの脅威からユーザーを保護します。

この投稿は、前回の発表(MC1191924年)を思い出させるものです。そこでは、今後のセキュリティ変更と、展開前に組織が取るべき対応について伝えていました。 

[展開スケジュール]

  • 一般公開(世界開始):2026年10月中旬から開始され、2026年10月下旬までに完了する予定です

[組織への影響]

影響を受ける人物

  • Microsoft Entra IDサインインページで認証している組織は、login.microsoftonline.com ホストされています
  • ブラウザ拡張機能、監視ツール、カスタマイズツール、またはサインイン体験にスクリプトを注入するその他のソリューションを使用している組織
  • Microsoft Entraの外部IDテナントは影響を受けません

ホームとサービス

  • Microsoft Entra ID
  • login.microsoftonline.com を用いたウェブベースの認証体験
  • 対応ブラウザ間でのブラウザベースのサインイン体験

何が起こるのか

  • Microsoft Entra IDのサインインページには新しいコンテンツセキュリティポリシー(CSP)ヘッダーが追加されます。
  • スクリプトは信頼できるMicrosoftコンテンツ配信ネットワーク(CDN)ドメインからのみ許可されます。
  • インラインスクリプトの実行は、信頼できるMicrosoft認証ソースに限定されます。
  • Microsoft Entra IDのサインインページにスクリプトを注入するブラウザ拡張機能やツールが動作を停止する可能性があります。
  • サポートされていないスクリプト注入ツールが機能しなくても、ユーザーは引き続きサインインできます。
  • この変更はサービスアップデートの一環としてデフォルトで有効化されており、テナント設定は必要ありません。
  • Microsoft Authentication Library(MSAL)およびAPIベースの認証フローは影響を受けません。なぜならCSPの強制は login.microsoftonline.com を使ったブラウザベースのサインイン体験にのみ適用されるためです。

[行動が必要と提言]

もし組織がMicrosoft Entra IDのサインインページにコードを注入するツールや拡張機能を使用していない場合、何の対応も必要ありません。

もしあなたの組織がサインイン体験にコードを注入するツールを使用している場合:

  • CSPのガイダンスを確認し、ツールやブラウザ拡張機能、カスタムソリューションがスクリプト注入に依存しているかどうかを評価してください。
  • 導入前に認証ワークフローをテストしてください。
  • Microsoft Entraのサインインページへのスクリプト注入に依存しているソリューションは、置き換えまたは更新してください。
  • ヘルプデスクやアイデンティティ管理チームに潜在的な影響を伝えましょう。
  • 内部ドキュメントに影響を受けた認証カスタマイズが記載されている場合は更新してください。

詳しくはこちら

[コンプライアンスの考慮事項]

コンプライアンス上の考慮事項は特定されていません。組織に応じた適切なレビューを行ってください。