Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Microsoft to Block External Scripts  in Entra ID Logins to Enhance Protections

Posted on November 28, 2025November 28, 2025 By CWS

Microsoft has introduced a major safety improve to its Microsoft Entra ID authentication course of, as a part of the corporate’s broader Safe Future Initiative.

Microsoft is updating its Content material Safety Coverage (CSP) to dam the execution of exterior scripts throughout person sign-ins.

This proactive measure is designed to protect organizations from evolving cyber threats, particularly cross-site scripting (XSS) assaults, the place hackers try and inject malicious code into professional web sites.

What Is Altering?

At the moment, some browser extensions or instruments might inject scripts into the sign-in web page to change its conduct or look. Beginning in mid-to-late October 2026, Microsoft will implement a stricter coverage on login.microsoftonline.com.

Below this new rule, solely scripts from trusted Microsoft domains shall be allowed to run. Any unauthorized or exterior code trying to execute in the course of the login course of shall be robotically blocked.

This transformation ensures that the sign-in expertise stays a closed, safe setting, stopping attackers from exploiting vulnerabilities in third-party scripts.

It is very important be aware that this replace applies solely to browser-based sign-ins on the precise Microsoft login URL; Microsoft Entra Exterior ID is not going to be affected.

Microsoft advises organisations to cease utilizing any browser extensions or customized instruments that modify the Entra ID sign-in web page through script injection.

Whereas the login course of itself will proceed to perform for customers, any instruments counting on injecting code will cease working as soon as the replace is enforced.

To prepare, IT directors ought to take a look at their sign-in flows forward of the 2026 deadline. You may establish potential points now by opening the developer console in your browser whereas signing in.

In case your group makes use of instruments that violate the brand new coverage, error messages will seem in purple textual content within the console.

Megna Kokkalera, Product Supervisor II at Microsoft, emphasised that this replace provides a vital layer of protection for person identities.

By eliminating the chance of unverified scripts, Microsoft ensures that organizations keep forward of rising safety threats whereas sustaining a seamless, safe sign-in expertise.

Directors are inspired to evaluate their environments early to make sure a easy transition when the coverage goes into impact globally subsequent yr.

Comply with us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:Block, Enhance, Entra, External, Logins, Microsoft, Protections, Scripts

Post navigation

Previous Post: London Councils’ IT Systems Impacted by CyberAttack, Including Phone Lines
Next Post: Comcast to Pay a $1.5 Million Fine to Settle an FCC Investigation Linked to Vendor Data Breach

Related Posts

Hackers Breaking Internet with 7.3 Tbps and 4.8 Billion Packets Per Second DDoS Attack Cyber Security News
Samsung MagicINFO 9 Server Vulnerability Let Attackers Write Arbitrary File Cyber Security News
Beware of Typosquatted Malicious PyPI Packages That Delivers SilentSync RAT Cyber Security News
Apache Tomcat Vulnerabilities Let Attackers Bypass Authentication & Trigger DoS Attacks Cyber Security News
New Active Directory Lateral Movement Techniques that Bypasses Authentication and Exfiltrate Data Cyber Security News
Salesforce Confirms that Customers’ Data Was accessed Following the Gainsight Breach Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • In Other News: HashJack AI Browser Attack, Charming Kitten Leak, Hacker Unmasked
  • Handala Hacker Group Attacking Israeli High-Tech and Aerospace Professionals
  • MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants
  • Comcast to Pay a $1.5 Million Fine to Settle an FCC Investigation Linked to Vendor Data Breach
  • Microsoft to Block External Scripts  in Entra ID Logins to Enhance Protections

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • In Other News: HashJack AI Browser Attack, Charming Kitten Leak, Hacker Unmasked
  • Handala Hacker Group Attacking Israeli High-Tech and Aerospace Professionals
  • MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants
  • Comcast to Pay a $1.5 Million Fine to Settle an FCC Investigation Linked to Vendor Data Breach
  • Microsoft to Block External Scripts  in Entra ID Logins to Enhance Protections

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark