Open
Cached
·
just now
22
directives
Content-Security-Policy
Content-Security-Policy: default-src none;script-src https://res.public.onecdn.static.microsoft https://res.df.onecdn.static.microsoft https://cdn.graph.office.net https://www.microsoft.com https://mwf-service.akamaized.net https://partnerresources.microsoft.com https://ajax.aspnetcdn.com https://az725175.vo.msecnd.net *.clarity.ms https://teams.microsoft.com https://az416426.vo.msecnd.net https://js.monitor.azure.com https://web.vortex.data.microsoft.com https://mem.gfx.ms https://wcpstatic.microsoft.com https://wcpstatic-int.microsoft.com https://browser.events.data.microsoft.com https://controls.account.microsoft.com:44308 https://amcdn.msftauth.net http://amcdn.msauth.net/ https://developer.microsoft.com https://graphprodblobstorage.blob.core.windows.net https://graph.office.net 'unsafe-inline' 'unsafe-eval';img-src https://res.public.onecdn.static.microsoft https://res.df.onecdn.static.microsoft https://cdn.graph.office.net https://c1.microsoft.com https://img-prod-cms-rt-microsoft-com.akamaized.net https://c.bing.com https://img-prod-cms-rt-microsoft-com.akamaized.net *.clarity.ms https://devblogs.microsoft.com https://web.vortex.data.microsoft.com https://storage.live.com https://store-images.s-microsoft.com https://store-iamges.microsoft.com https://musicimage.xboxlive.com https://arc.msn.com https://developer.microsoft.com https://graphprodblobstorage.blob.core.windows.net data:;style-src https://res.public.onecdn.static.microsoft https://res.df.onecdn.static.microsoft https://cdn.graph.office.net https://partnerresources.microsoft.com https://www.microsoft.com https://statics-marketingsites-wcus-ms-com.akamaized.net https://statics-marketingsites-eus-ms-com.akamaized.net https://statics-marketingsites-neu-ms-com.akamaized.net https://mwf-service.akamaized.net https://developer.microsoft.com https://graphprodblobstorage.blob.core.windows.net https://graph.office.net 'unsafe-inline';style-src-elem https://res.public.onecdn.static.microsoft https://res.df.onecdn.static.microsoft https://cdn.graph.office.net https://partnerresources.microsoft.com https://www.microsoft.com https://statics-marketingsites-wcus-ms-com.akamaized.net https://statics-marketingsites-eus-ms-com.akamaized.net https://statics-marketingsites-neu-ms-com.akamaized.net https://mwf-service.akamaized.net https://developer.microsoft.com https://graphprodblobstorage.blob.core.windows.net https://graph.office.net 'unsafe-inline';font-src https://res.public.onecdn.static.microsoft https://res.df.onecdn.static.microsoft https://cdn.graph.office.net https://c.s-microsoft.com https://www.microsoft.com https://partnerresources.microsoft.com https://static2.sharepointonline.com https://spoprod-a.akamaihd.net https://res-1.cdn.office.net https://res.cdn.office.net https://developer.microsoft.com https://graphprodblobstorage.blob.core.windows.net https://graph.office.net;connect-src https://dc.services.visualstudio.com https://browser.events.data.microsoft.com https://web.vortex.data.microsoft.com *.clarity.ms https://browser.pipe.aria.microsoft.com https://res.public.onecdn.static.microsoft https://res.df.onecdn.static.microsoft https://cdn.graph.office.net https://consentreceiverfd-prod.azurefd.net https://login.microsoftonline.com https://login.live.com https://www.microsoft.com https://statics.teams.microsoft.com https://controls.account.microsoft.com:44308 https://amcdn.msftauth.net http://amcdn.msauth.net/ https://mem.gfx.ms https://developer.microsoft.com https://graphprodblobstorage.blob.core.windows.net;form-action https://developer.microsoft.com/;frame-ancestors https://developer.microsoft.com;frame-src https://www.microsoft.com https://controls.account.microsoft-dev.com:44308 https://controls.account.microsoft.com:44308 https://login.microsoftonline.com https://login.live.com https://amcdn.msftauth.net http://amcdn.msauth.net/ https://mem.gfx.ms https://microsoft-onmicrosoft-com.access.mcas.ms/ https://developer.microsoft.com https://graphprodblobstorage.blob.core.windows.net;worker-src https://developer.microsoft.com;base-uri none;child-src ;manifest-src ;media-src ;object-src Content-Security-Policy-Report-Only: object-src 'none';script-src 'nonce-nonce-m365devportals' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https:;base-uri 'none';trusted-types default 1DSScriptURL MeControlScriptURL goog#html dompurify editorViewLayer domLineBreaksComputer tokenizeToString editorGhostText defaultWorkerFactory standaloneColorizer diffReview diffEditorWidget adaptivecards#deprecatedExportedFunctionPolicy adaptivecards#markdownPassthroughPolicy adaptivecards#restoreContentsPolicy;require-trusted-types-for 'script';report-uri https://csp.microsoft.com/report/M365DeveloperPortals-PROD
default-src
Host
—
script-src
Host
—
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
img-src
Host
—
img-src
Host
—
img-src
Scheme
—
data:
style-src
Keyword
—
'unsafe-inline'
style-src-elem
Keyword
—
'unsafe-inline'
connect-src
Host
—
frame-src
Host
—
base-uri
Host
—
child-src
Source
—
(no sources)
manifest-src
Source
—
(no sources)
media-src
Source
—
(no sources)
object-src
Source
—
(no sources)
Content-Security-Policy-Report-Only
object-src
Keyword
—
'none'
script-src
Nonce
—
'nonce-nonce-m365devportals'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
script-src
Keyword
—
'strict-dynamic'
script-src
Scheme
—
https:
base-uri
Keyword
—
'none'
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
trusted-types
Host
—
require-trusted-types-for
Keyword
—
'script'