Hi,
I have been reviewing the security controls relating to a Dynamics 365 Finance and Operations installation and I have noticed that there is a lack of Content Security Policy browser directives in the content.
Only "Content-Security-Policy: frame-ancestors 'self'" appears to be active, but we would typically want to define other CSP directives to remove directive ambiguity i.e., missing CSP Directives, with no fall-back.
As I don't operate the environment, is there a config setting where CSP directives can be individually activated? We allow our users to use Edge, Chrome and Firefox to interact with Dynamics 365, therefore want to provide more contemporary security directives to the client browsers connecting to the service.
What settings exist or is there a recommended approach to implement more granular CSP directives, without breaking any Dynamics 365 content?
Example CSP directive:
Other References:
André Arnaud de Cal...
291,965
Super User 2025 Season 1
Martin Dráb
230,817
Most Valuable Professional
nmaenpaa
101,156