New Content Security Policy (CSP) Enforcement

CSP

Microsoft is rolling out strict Content Security Policy (CSP) enforcement starting Jan 2026.

  • After Jan 30, 2026, Power Apps will block external scripts, images, and API calls by default.
  • If you want your app to use them, you must add those external sources to the allowlist.

If your app is business-critical, go to Power Platform Admin Center:

  1. ✅Temporarily turn OFF CSP enforcement.
  2. ✅Turn ON reporting mode.
  3. ✅Test your app and see which external sources get flagged.
  4. ✅Add required sources to the allowlist
  5. ✅Turn CSP enforcement back on

This is the safest way to understand exactly what your app depends on before enforcement becomes mandatory.

If your app doesn’t rely on external assets keep enforcement on, but I’d still suggest enabling reporting to proactively spot issues.

Microsoft has shared detailed guidance here: https://learn.microsoft.com/en-us/power-apps/developer/code-apps/how-to/content-security-policy

Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *

Subscribe to Newsletter

Subscribe to our email newsletter to get the latest posts delivered right to your email.
Powered by Amail.