Microsoft is preparing a major security shift in Entra ID, announcing that starting next October, only scripts from trusted Microsoft domains will run during login. The move aims to curb long-standing cross-site scripting vulnerabilities that continue to surface across modern applications. The company says the update reflects lessons from recent nation-state breaches and urged organizations to test their sign-in flows ahead of the rollout.
