Content Security Policies (CSP) are coming to SharePoint Online and might impact your custom SPFx solutions
Starting March 1, 2026, SharePoint Online will enforce Content Security Policy (CSP), blocking scripts from non-trusted sources in custom SPFx solutions. To avoid disruption, ensure all scripts come from trusted sources and move inline scripts to files. CSP enforcement can be postponed 90 days via PowerShell. We’re improving SharePoint Online security via Content Security Policy (CSP) enforcement. Currently CSP is applied in reporting mode but as of March 1, 2026, the Content Security Policy will be enforced which will prevent the loading of script (e.g. JavaScript) from non-allowed sources. This message center post replaces MC1055557 (April 2024). This change is associated with Microsoft 365 Roadmap ID: 485797 When this will happen: This will be implemented starting March 1, 2026. How this will affect your organization: If your organization extended SharePoint Online using SPFx then the created custom SPFx solutions could potentially load scripts from locations which are not allowed. In most cases SPFx solutions use and load script from allowed locations, but that’s not always the case. Any script from a not allowed location will be blocked, the same applies for any inline script usage. SPFx solutions whose script is getting blocked will not function anymore as designed, impacting business scenarios depending on those solutions. To prevent solutions from breaking there you need to: Ensure all used script locations are trusted script sources. This can be done without updating the SPFx solution Move all inline script to script files which can then be defined as trusted source. This will require updating the SPFx solution! If you need more time to review your SPFx solutions, there’s an option to postpone CSP enforcement by 90 days via below SPO Management Shell PowerShell cmdlet. Set-SPOTenant -DelayContentSecurityPolicyEnforcement $true Note: This option will be available in the SPO Management Shell version 16.0.26712.12000 (November 2025) or higher. What you need to do to prepare: In addition to the default CSP settings, SharePoint Online will add locations listed in the Trusted Script Sources area of the SharePoint Online Admin Center as valid locations for CSP, thus enabling script loading from those locations. To add an entry, in […]
The post Content Security Policies (CSP) are coming to SharePoint Online and might impact your custom SPFx solutions appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Content Security Policies (CSP) are coming to SharePoint Online and might impact your custom SPFx solutions
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Excel: Excel canvas
Excel canvas, a new Copilot feature in Microsoft Excel, creates dynamic reports with visualizations and insights that update automatically wit...
Dynamics 365 Contact Center – Use role-based enforcement for recording and transcription downloads
We are announcing the ability to use role-based enforcement for recording and transcription downloads in Dynamics 365 Contact Center. This fea...
Microsoft Outlook: Right-click to customize the classic ribbon
Microsoft Outlook now allows users to customize the classic ribbon by right-clicking on the Home or View tab to select commands and arrange th...
Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs
Starting October 10, 2026, Exchange Online tenants must configure EWSAllowedAppIDs to allow Exchange Web Services (EWS) access; EWSEnabled=Tru...
Microsoft Entra App Gallery: Self-service onboarding for new applications
Microsoft Entra App Gallery introduces self-service onboarding for new applications, allowing ISVs to validate SSO and provisioning integratio...
Upgraded call history in Teams Calls app
Teams Calls app call history is upgraded to consolidate missed calls and voicemails into single entries and expand history from 100 to 3,000 r...
Power Automate – Enable Process Intelligence Studio in object-centric process mining
We are announcing the availability of Process Intelligence Studio in object-centric process mining in Power Automate Process Mining. This feat...
Dynamics 365 Contact Center – Use after conversation presence status for wrap-up activities
We are announcing the ability to use after conversation presence status for wrap-up activities in Dynamics 365 Contact Center. This feature wi...
Dynamics 365 Finance and Operations cross-app: Migrate finance and operations environments from Lifecycle Services to Power Platform admin center
The self-service environment migration feature moves management of an existing finance and operations apps environment from Microsoft Dynamics...
Microsoft Teams: Start side conversations during meetings
Keep collaboration moving without disrupting the main discussion. Start and continue one-to-one or small-group conversations directly from a m...