web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

No record found.

Community site session details

Community site session details

Session Id :
Finance | Project Operations, Human Resources, ...
Unanswered

Content Security Policy (CSP) browser attributes inclusion or activation

(0) ShareShare
ReportReport
Posted on by 5

Hi,

I have been reviewing the security controls relating to a Dynamics 365 Finance and Operations installation and I have noticed that there is a lack of Content Security Policy browser directives in the content.

Only "Content-Security-Policy: frame-ancestors 'self'" appears to be active, but we would typically want to define other CSP directives to remove directive ambiguity i.e., missing CSP Directives, with no fall-back.

As I don't operate the environment, is there a config setting where CSP directives can be individually activated?  We allow our users to use Edge, Chrome and Firefox to interact with Dynamics 365, therefore want to provide more contemporary security directives to the client browsers connecting to the service.

What settings exist or is there a recommended approach to implement more granular CSP directives, without breaking any Dynamics 365 content?

Example CSP directive:

  • plugin-types
  • report-uri
  • referrer
  • form-action
  • base-uri
  • sandbox
  • reflected-xss

Other References:

I have the same question (0)

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Neeraj Kumar – Community Spotlight

We are honored to recognize Neeraj Kumar as our Community Spotlight honoree for…

Leaderboard > Finance | Project Operations, Human Resources, AX, GP, SL

#1
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 449 Super User 2025 Season 2

#2
Martin Dráb Profile Picture

Martin Dráb 422 Most Valuable Professional

#3
BillurSamdancioglu Profile Picture

BillurSamdancioglu 239 Most Valuable Professional

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans