web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

No record found.

News and Announcements icon
Community site session details

Community site session details

Session Id :
Finance | Project Operations, Human Resources, ...
Unanswered

Content Security Policy (CSP) browser attributes inclusion or activation

(0) ShareShare
ReportReport
Posted on by 5

Hi,

I have been reviewing the security controls relating to a Dynamics 365 Finance and Operations installation and I have noticed that there is a lack of Content Security Policy browser directives in the content.

Only "Content-Security-Policy: frame-ancestors 'self'" appears to be active, but we would typically want to define other CSP directives to remove directive ambiguity i.e., missing CSP Directives, with no fall-back.

As I don't operate the environment, is there a config setting where CSP directives can be individually activated?  We allow our users to use Edge, Chrome and Firefox to interact with Dynamics 365, therefore want to provide more contemporary security directives to the client browsers connecting to the service.

What settings exist or is there a recommended approach to implement more granular CSP directives, without breaking any Dynamics 365 content?

Example CSP directive:

  • plugin-types
  • report-uri
  • referrer
  • form-action
  • base-uri
  • sandbox
  • reflected-xss

Other References:

I have the same question (0)

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Introducing the 2026 Season 1 community Super Users

Congratulations to our 2026 Super Stars!

Congratulations to our 2025 Community Spotlights

Thanks to all of our 2025 Community Spotlight stars!

Leaderboard > Finance | Project Operations, Human Resources, AX, GP, SL

#1
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 545 Super User 2026 Season 1

#2
Giorgio Bonacorsi Profile Picture

Giorgio Bonacorsi 408

#3
Adis Profile Picture

Adis 267 Super User 2026 Season 1

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans