SharePoint Online: Content Security Policy Control in Tenant Administration

Message Information

Severity normal
Timeline
Start Date April 15, 2025
End Date June 30, 2025
Last Modified April 15, 2025
Services
SharePoint Online
CategoryStayInformed

Message Details

SharePoint Online Tenant Administrators can now allow script sources for modern pages in SharePoint sites. This feature is particularly useful in scenarios where modern pages have custom code that loads scripts (e.g., TypeScript code) from external sources like a content delivery network (CDN). SharePoint will now report to administrators where sources that have not been allowed are loaded from, providing a way for administrators to identify those sources and take action. Tenant Administrators can also enforce browsers to only load scripts from allowed sources. This behavior can be enabled using SharePoint Online Management Shell.

When this will happen:

Targeted Release: We will begin rolling out on late March 2025 and expect to complete by early April 2025.

General Availability (Worldwide): We will begin rolling out on late April 2025 and expect to complete by late April 2025.

General Availability (GCC, GCC High, DoD): We will begin rolling out on late April 2025 and expect to complete by mid-May 2025.

How this will affect your organization:

Tenant Administrators will have the option to control and govern where custom code loads scripts and, if needed, enforce browsers to only load scripts from trusted sources. A new “Trusted script sources” page will give administrators control over which source can be trusted to load scripts.

3b34c585 d76a 4298 9e27 888804978fbb

60c8e8ab 6f88 4d18 870f 3114006b7141

39c433d2 d7ed 4530 bcdb 0f774aa44c0a

3b34c585 d76a 4298 9e27 888804978fbb

23bb2ec6 cf5f 40c1 84fd 439be67e0055

What you need to do to prepare:

This rollout will happen automatically with no admin action required.