SharePoint: HTML pages

🚨 The Signal: SharePoint will support HTML pages, creatable via Copilot or upload. This introduces new content vectors and potential for client-side vulnerabilities, requiring updated content governance and security policies.

The Impact

SharePoint authors and Copilot users are affected, with a security risk of increased client-side vulnerabilities and content governance challenges.

  • SharePoint authors: New content creation methods may bypass existing security controls.
  • Copilot users: AI-generated HTML could introduce insecure code or misconfigurations.
  • Admins: Need to update content policies and security baselines for HTML pages.
  • Security teams: Increased attack surface from new content types requires monitoring.

The Action

  1. Review and update SharePoint content governance policies to explicitly address HTML page creation and upload.
  2. Assess existing SharePoint security baselines for applicability to HTML content and client-side scripting.
  3. Develop guidance for users on secure HTML page creation, especially when using Copilot.
  4. Monitor SharePoint audit logs for unusual HTML page creation or modification activities.
  5. Evaluate Microsoft Purview Data Loss Prevention (DLP) policies for HTML content types.

Domain: SharePoint · Impact: high · Workload: SharePoint