(Updated) Updates to custom scripting in sites and Classic Publishing site creation
🚨 The Signal: SharePoint Online will disable custom scripting by default for new and existing classic publishing sites. A new setting allows managing site property bag values without enabling custom scripting, reducing a common security risk.
The Impact
SharePoint administrators are affected by reduced attack surface from disabled custom scripting, improving overall site security.
- SharePoint Admins: Reduced risk from malicious scripts on classic publishing sites.
- Security Teams: Improved compliance with secure configuration baselines.
- Developers: Property bag management is now more secure without broad script enablement.
The Action
- Review existing classic publishing sites for reliance on custom scripting.
- Utilize the new AllowWebPropertyBagUpdateWhenDenyAddAndCustomizePagesIsEnabled setting for property bag management.
- Ensure any necessary custom scripts are deployed via approved, secure methods.
Domain: SharePoint · Impact: medium · Workload: SharePoint · Essential Eight: User Application Hardening · ISM: ISM-1412, ISM-1485, ISM-1486, ISM-1542, ISM-1585, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1823, ISM-1824, ISM-1859, ISM-1860