Okay I get why this change sounds great, but I'm pretty sure a consequence is that password managers will no longer autofill on Entra sign-in pages. That will likely lead to weaker credentials or weaker storage of them. That feels like a net loss.
UPDATE: All's well, mostly. Because of the way that extension-based password managers add their content, they should be exempted from this policy. Basically, if they don't add inline scripts, they're golden. KeePassXC and Bitwarden do not; I presume 1Password does not either. Sorry for the false alarm.
Enhance protection of Microsoft Entra ID authentication by blocking external script injection | Microsoft Community Hub
Microsoft is further enhancing security of the Microsoft Entra ID authentication experience by blocking external script injection. [Action may be required]
