Open
Cached
·
just now
6
directives
Content-Security-Policy
Content-Security-Policy: base-uri 'self'; script-src 'strict-dynamic' https://www.clarity.ms https://ai.microsoftol.com https://copilot.microsoft.com https://copilot.com https://challenges.cloudflare.com/ https://fpt.dfp.microsoft.com/ https://assets.msn.com 'self' 'nonce-MPhMCRGw21BUYMpvBRgcvw==' *.paypal.com *.paypalobjects.com; frame-ancestors 'self' https://edgeservices.bing.com edge://* *.microsoft365.com *.office.com m365.cloud.microsoft copilot.cloud.microsoft ccm.mobile.m365.svc.cloud.microsoft copilot.cloud-dev.microsoft; require-trusted-types-for 'script'; trusted-types default lit-html copilotPolicy dompurify @centro/hvc-loader fast-html base-html-policy @office/dime#webpack paypal-web-sdk; report-to csp-endpoint
base-uri
Keyword
—
'self'
script-src
Keyword
—
'strict-dynamic'
script-src
Host
—
script-src
Keyword
—
'self'
script-src
Nonce
—
'nonce-MPhMCRGw21BUYMpvBRgcvw=='
frame-ancestors
Keyword
—
'self'
frame-ancestors
Host
—
edge://*
require-trusted-types-for
Keyword
—
'script'
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
report-to
Host
—
Content-Security-Policy-Report-Only
No report-only CSP headers found.