(Updated) Updates to custom scripting in sites and Classic Publishing site creation

🚨 The Signal: SharePoint Online will disable custom scripting by default for new and existing classic publishing sites. A new setting allows managing site property bag values without enabling custom scripting, reducing a common security risk.

The Impact

SharePoint administrators are affected by reduced attack surface from disabled custom scripting, improving overall site security.

  • SharePoint Admins: Reduced risk from malicious scripts on classic publishing sites.
  • Security Teams: Improved compliance with secure configuration baselines.
  • Developers: Property bag management is now more secure without broad script enablement.

The Action

  1. Review existing classic publishing sites for reliance on custom scripting.
  2. Utilize the new AllowWebPropertyBagUpdateWhenDenyAddAndCustomizePagesIsEnabled setting for property bag management.
  3. Ensure any necessary custom scripts are deployed via approved, secure methods.

Domain: SharePoint · Impact: medium · Workload: SharePoint · Essential Eight: User Application Hardening · ISM: ISM-1412, ISM-1485, ISM-1486, ISM-1542, ISM-1585, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1823, ISM-1824, ISM-1859, ISM-1860