Open
Cached
·
just now
22
directives
Content-Security-Policy
Content-Security-Policy: base-uri 'self'; child-src 'self' https://amcdn.msftauth.net https://outlook.exo.eaglex.ic.gov https://outlook.exo.microsoft.scloud https://outlook.office.com https://outlook.office365.us https://partner.outlook.cn https://shell.azurefd.eaglex.ic.gov https://shell.azurefd.microsoft.scloud https://shell.cdn.office.net https://shellppe.cdn.office.net https://webmail.apps.mil https://webshell.dodsuite.office365.us https://webshell.suite.eaglex.ic.gov https://webshell.suite.microsoft.scloud https://webshell.suite.office.com https://webshell.suite.office365.us https://webshell.suite.officeppe.com https://webshell.suite.partner.microsoftonline.cn; connect-src 'self' https: wss://*.augloop.svc.cloud.microsoft/ wss://*.delve.office.com/ wss://*.rt.yammer.com/cometd/ wss://augloop.svc.cloud.microsoft/; default-src 'none'; font-src 'self' data: https://*.cdn.office.net/ https://*.delve.office.com/ https://*.engage.cloud.microsoft/ https://*.res.office365.com/ https://aesir.office.com https://c.s-microsoft.com https://engage.cloud.microsoft/ https://engage.usgovcloud.microsoft/ https://maxcdn.bootstrapcdn.com/bootstrap/ https://res-1.cdn.office.net https://res-1.public.onecdn.static.microsoft/ https://res-2.public.onecdn.static.microsoft/ https://res-4.public.onecdn.static.microsoft/ https://res-gcch.onecdn.usgovcloud-static.microsoft/ https://res.public.onecdn.static.microsoft/ https://spoprod-a.akamaihd.net/ https://static2.sharepointonline.com https://thumbnails.yammer.com/ https://web.yammer.com/ https://www.microsoft.com https://www.yammer.com/; form-action 'self' https:; frame-ancestors 'self' https:; frame-src 'self' blob: https:; img-src 'self' blob: data: https:; manifest-src 'self' https://*.cdn.office.net/ https://*.res.office365.com/ https://res-1.public.onecdn.static.microsoft/ https://res-2.public.onecdn.static.microsoft/ https://res-4.public.onecdn.static.microsoft/ https://res-gcch.onecdn.usgovcloud-static.microsoft/ https://res.public.onecdn.static.microsoft/; media-src 'self' blob: https://*.cdn.office.net/ https://*.engage.cloud.microsoft/ https://*.sharepoint.com https://engage.cloud.microsoft/ https://engage.usgovcloud.microsoft/ https://web.yammer.com/ https://www.yammer.com/; object-src 'none'; report-to csp-endpoint; report-uri https://csp.microsoft.com/report/VivaEngage-Web-PROD; script-src 'nonce-qDzvuQ1d1+erw85FP/c9aoFg0t9RSug43S+wPdRY5CU=' 'report-sample' 'self' 'strict-dynamic' https://*.cdn.office.net/ https://*.delve.office.com/ https://*.engage.cloud.microsoft/ https://*.microsoft.com https://*.res.office365.com/ https://*.visualstudio.com/ https://a-ring.msedge.net https://acdc-direct.office.com https://admin.microsoft.com https://aesir.office.com https://afd-a-acdc-direct.office.com https://afd-k-acdc-direct.office.com https://amcdn.msauth.net/ https://amcdn.msftauth.net/ https://atm-fp-direct.office.com https://b-ring.msedge.net https://dev.azure.com/ https://engage.cloud.microsoft/ https://engage.usgovcloud.microsoft/ https://gtm-dyn-direct.office365.com https://js.monitor.azure.com/ https://k-ring.msedge.net https://outlook.exo.eaglex.ic.gov https://outlook.exo.microsoft.scloud https://outlook.live.com https://outlook.office.com https://outlook.office365.us https://ow1.res.office365.com https://partner.outlook.cn https://r4.res.office365.com https://res-1.public.onecdn.static.microsoft/ https://res-2.public.onecdn.static.microsoft/ https://res-4.public.onecdn.static.microsoft/ https://res-gcch.onecdn.usgovcloud-static.microsoft/ https://res.public.onecdn.static.microsoft/ https://s-ring.msedge.net https://shell.azurefd.eaglex.ic.gov https://shell.azurefd.microsoft.scloud https://shellprod.msocdn.com https://statics.teams.cloud.microsoft https://statics.teams.microsoft.com https://substrate.office.com https://web.vortex.data.microsoft.com https://web.yammer.com/ https://webmail.apps.mil https://webshell.dodsuite.office365.us https://webshell.suite.eaglex.ic.gov https://webshell.suite.microsoft.scloud https://webshell.suite.office.com https://webshell.suite.office365.us https://webshell.suite.officeppe.com https://webshell.suite.partner.microsoftonline.cn https://www.yammer.com/ wss://*.delve.office.com; script-src-attr 'report-sample' 'self'; script-src-elem 'self' blob: https://*.cdn.office.net.rproxy.goskope.com/ https://*.cdn.office.net/ https://*.engage.cloud.microsoft/ https://*.res.office365.com/ https://amcdn.msauth.net/ https://amcdn.msftauth.net/ https://engage.cloud.microsoft/ https://engage.usgovcloud.microsoft/ https://js.monitor.azure.com/ https://res-1.public.onecdn.static.microsoft/ https://res-2.public.onecdn.static.microsoft/ https://res-4.public.onecdn.static.microsoft/ https://res-gcch.onecdn.usgovcloud-static.microsoft/ https://res.public.onecdn.static.microsoft/ https://web.yammer.com/ https://www.yammer.com/; style-src 'report-sample' 'self' 'unsafe-inline' https://*.cdn.office.net/ https://*.engage.cloud.microsoft/ https://*.res.office365.com/ https://*.visualstudio.com/ https://dev.azure.com/ https://engage.cloud.microsoft/ https://engage.usgovcloud.microsoft/ https://res-1.public.onecdn.static.microsoft/ https://res-2.public.onecdn.static.microsoft/ https://res-4.public.onecdn.static.microsoft/ https://res-gcch.onecdn.usgovcloud-static.microsoft/ https://res.public.onecdn.static.microsoft/ https://shell.azurefd.eaglex.ic.gov https://shell.azurefd.microsoft.scloud https://shellprod.msocdn.com https://web.yammer.com/ https://www.microsoft.com https://www.yammer.com/; style-src-attr 'report-sample' 'self' 'unsafe-inline' https://*.cdn.office.net/ https://*.engage.cloud.microsoft/ https://*.res.office365.com/ https://engage.cloud.microsoft/ https://engage.usgovcloud.microsoft/ https://res-1.public.onecdn.static.microsoft/ https://res-2.public.onecdn.static.microsoft/ https://res-4.public.onecdn.static.microsoft/ https://res-gcch.onecdn.usgovcloud-static.microsoft/ https://res.public.onecdn.static.microsoft/ https://web.yammer.com/ https://www.yammer.com/; style-src-elem 'self' 'unsafe-inline' https://*.cdn.office.net/ https://*.engage.cloud.microsoft/ https://*.res.office365.com/ https://*.visualstudio.com/ https://dev.azure.com/ https://engage.cloud.microsoft/ https://engage.usgovcloud.microsoft/ https://res-1.public.onecdn.static.microsoft/ https://res-2.public.onecdn.static.microsoft/ https://res-4.public.onecdn.static.microsoft/ https://res-gcch.onecdn.usgovcloud-static.microsoft/ https://res.public.onecdn.static.microsoft/ https://visualsponline.azurewebsites.net/app/js/ https://web.yammer.com/ https://www.yammer.com/; upgrade-insecure-requests; worker-src 'self' blob: https://*.cdn.office.net/ https://engage.cloud.microsoft/ https://engage.usgovcloud.microsoft/ https://res-1.public.onecdn.static.microsoft/ https://res-2.public.onecdn.static.microsoft/ https://res-4.public.onecdn.static.microsoft/ https://res-gcch.onecdn.usgovcloud-static.microsoft/ https://res.public.onecdn.static.microsoft/ https://web.yammer.com/
base-uri
Keyword
—
'self'
child-src
Keyword
—
'self'
child-src
Host
—
child-src
Host
—
child-src
Host
—
child-src
Host
—
child-src
Host
—
child-src
Host
—
connect-src
Keyword
—
'self'
connect-src
Scheme
—
https:
connect-src
Host
—
default-src
Keyword
—
'none'
font-src
Keyword
—
'self'
font-src
Scheme
—
data:
form-action
Keyword
—
'self'
form-action
Scheme
—
https:
frame-ancestors
Keyword
—
'self'
frame-ancestors
Scheme
—
https:
frame-src
Keyword
—
'self'
frame-src
Scheme
—
blob:
frame-src
Scheme
—
https:
img-src
Keyword
—
'self'
img-src
Scheme
—
blob:
img-src
Scheme
—
data:
img-src
Scheme
—
https:
manifest-src
Keyword
—
'self'
media-src
Keyword
—
'self'
media-src
Scheme
—
blob:
object-src
Keyword
—
'none'
report-to
Host
—
script-src
Nonce
—
'nonce-qDzvuQ1d1+erw85FP/c9aoFg0t9RSug43S+wPdRY5CU='
script-src
Keyword
—
'report-sample'
script-src
Keyword
—
'self'
script-src
Keyword
—
'strict-dynamic'
script-src
Host
—
script-src
Host
—
script-src
Host
—
script-src
Host
—
script-src
Host
—
script-src
Host
—
script-src
Host
—
script-src
Host
—
script-src-attr
Keyword
—
'report-sample'
script-src-attr
Keyword
—
'self'
script-src-elem
Keyword
—
'self'
script-src-elem
Scheme
—
blob:
script-src-elem
Host
—
ASN
|
MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation
style-src
Keyword
—
'report-sample'
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
style-src
Host
—
style-src
Host
—
style-src-attr
Keyword
—
'report-sample'
style-src-attr
Keyword
—
'self'
style-src-attr
Keyword
—
'unsafe-inline'
style-src-elem
Keyword
—
'self'
style-src-elem
Keyword
—
'unsafe-inline'
upgrade-insecure-requests
Source
—
(no sources)
worker-src
Keyword
—
'self'
worker-src
Scheme
—
blob:
Content-Security-Policy-Report-Only
No report-only CSP headers found.