web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Automate / SharePoint2019 Content...
Power Automate
Unanswered

SharePoint2019 Content-Security-Policy  is not opening out of box popups and default icons ( default-src 'self and frame-ancestors 'none')

(0) ShareShare
ReportReport
Posted on by Microsoft Employee

Currently I am working on SharePoint 2019 Penetration Test issue fixing. I am not able to find the fix details for two Content-Security-Policy properties (frame-ancestors 'none' and object-src 'self') in SharePoint 2019 on premises.

 

a. Content-Security-Policy: default-src 'self';

I have received below error message after applying "default-src 'self'". in SharePoint 2019 web config.

<add name="Content-Security-Policy" value="default-src 'self';"/>

Error Message:

Refused to execute inline event handler because it violates the following Content Security Policy directive: "default-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-...'), or a nonce ('nonce-...') is required to enable inline execution. Note that hashes do not apply to event handlers, style attributes and javascript&colon; navigations unless the 'unsafe-hashes' keyword is present. Note also that 'script-src' was not explicitly set, so 'default-src' is used as a fallback.

 

b. Content-Security-Policy: frame-ancestors 'none'.

SharePoint Out Of Box popups are not working after applying "frame-ancestors 'none'". in SharePoint 2019 web config and getting the below error message.

<add name="Content-Security-Policy" value="frame-ancestors 'none';"/>

Error Message: Refused to frame 'http://sharepoint.testing.com/ because an ancestor violates the following Content Security Policy directive: "frame-ancestors 'none'".

 

I am not able find the issue fix details in google. kindly someone help to provide at least Risk Acceptance MS Links to close this issue or provide if have a solution.

Categories:
I have the same question (0)

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Introducing the 2026 Season 1 community Super Users

Congratulations to our 2026 Super Users!

Kudos to our 2025 Community Spotlight Honorees

Congratulations to our 2025 community superstars!

Leaderboard > Power Automate

#1
Haque Profile Picture

Haque 67

#2
David_MA Profile Picture

David_MA 64 Super User 2026 Season 1

#3
Expiscornovus Profile Picture

Expiscornovus 39 Most Valuable Professional

Last 30 days Overall leaderboard