Tuesday, 10 March 2026

Microsoft SharePoint Online Security Update

Stay in the know with insights on our enterprise-class software and consulting services designed to unlock the full potential of Microsoft SharePoint and Microsoft 365.

Hello,


We'd like to inform you about a recent Microsoft platform change affecting SharePoint Online that may impact solutions built using the SharePoint Framework (SPFx), including Bamboo products such as Alert Plus.


Beginning March 1, 2026, Microsoft started rolling out Content Security Policy (CSP) enforcement for SharePoint Online. CSP is a security mechanism designed to restrict how scripts execute within SharePoint pages and to ensure that only trusted sources of code are allowed.


What Changed



Our development team had already prepared for the previously announced CSP enforcement, which focused on preventing SPFx solutions from loading JavaScript or CSS assets from outside the SPFx package. We addressed this requirement several weeks ago to ensure our solutions complied with Microsoft’s guidance.


However, Microsoft has recently begun enforcing additional CSP restrictions that were not previously expected, specifically blocking the use of inline JavaScript event handlers (such as onclick) within SharePoint pages.


Because SharePoint Online enforces CSP at the platform level, SPFx solutions cannot relax or bypass these restrictions. As a result, some functionality within SPFx-based solutions may require adjustments to comply with the updated policy.

This change may affect any SharePoint Online solution that relies on inline event handlers, including custom SPFx solutions or third-party SharePoint apps.


Impact


This change will not break Bamboo solutions, and all products will continue to load and operate normally within SharePoint Online. However, some specific functions that relied on inline event handlers may not behave as expected for users or administrators until updates are applied.


What Bamboo is Doing


Our engineering team is actively reviewing this additional enforcement across our entire product line. We currently have all hands focused on identifying and updating any affected functionality.


Where needed, we will release updated versions or hotfixes for affected Bamboo products, including Alert Plus, to ensure full compatibility with Microsoft’s updated CSP policies.


What You Need to Do


At this time, no action is required from your team.


If updates are required for any Bamboo products installed in your environment, we will provide new releases along with installation guidance for your administrators.


For customers who are not currently on active Bamboo support, please contact Sales@BambooSolutions.com so we can assist your organization with getting back on support, either through a maintenance catch-up program or one of our subscription plans.


We will continue to notify our user base as our review progresses and as updated versions become available.


Our Commitment


Microsoft platform updates occasionally introduce new security enforcement measures that require SPFx solutions to adapt. We are actively monitoring this rollout and working to ensure Bamboo products remain fully compatible with the SharePoint Online platform.


If you notice any unexpected behavior in your Bamboo solutions, please contact our support team and we will assist you promptly.


Thank you for your continued partnership with Bamboo Solutions.


Best regards,

Rob Manfredi

President

Bamboo Solutions


Email  Facebook  Instagram  LinkedIn  Web  X  YouTube

Our mailing address is:

Bamboo Solutions12110 Sunset Hills Rd #600 Reston, VA 20165 US

Want to change how you receive these emails?

Shadow AI is growing fast—do you have visibility?

                                                           
 
Unapproved AI tools are creating new blind spots across today's environments.
 
 
 
 
 
Hi Rupert,

AI tools are appearing across organizations faster than most IT teams can track. As employees adopt unapproved AI apps to streamline daily tasks, they also create new visibility gaps that traditional security tools often miss.

In this webinar, we'll break down what this rise of "Shadow AI" means for your organization, including:

  • Where unapproved AI tools commonly appear--and the data risks they introduce
  • Why today's distributed environments make Shadow AI harder to detect
  • The visibility gaps created by AI‑driven user behavior
  • Practical ways to simplify security operations without slowing down your workforce
  • Frameworks that make policy enforcement and ongoing management more consistent

If you're looking for clear guidance on how to stay ahead of emerging AI‑driven risks, this session will give you actionable steps to strengthen your security posture.

Save your spot now.

 
 
Our Speaker
 
 
 
 
Gus Fernandez
 
 
 
Consulting System Security Engineer
 
 
 
Barracuda Networks
 
 
   
 
 
 

Don't wait, register today!