-
Notifications
You must be signed in to change notification settings - Fork 233
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Impact Analysis - Microsoft change to Sharepoint custom scripting options could impact MS.SHAREPOINT.4.1v1 and 4.2 #977
Comments
Notes: In March 2024:
New PowerShell Command "DelayDenyAddAndCustomizePagesEnforcement":
Need to test:
|
Additional Notes: Post November: The NoScriptSite setting will be configured to True for all existing SharePoint sites and OneDrive sites except for below mentioned sites templates. BLANKINTERNETCONTAINER#0 = Classic Publishing Portal site CMSPUBLISHING#0 = Publishing Site BLANKINTERNET#0 = Publishing Site GROUP#0 = Team site APPCATALOG#0 = App Catalog CSPCONTAINER#0 = CSP Container The execution of existing scripts in OneDrive and SharePoint sites will remain unaffected. Any modifications made to a site will be automatically reverted to False status within 24 hours, unless the new PowerShell command “DelayDenyAddAndCustomizePagesEnforcement” is used prior to mid-November 2024 (previously May). After mid-November 2024, the 24-hour reversion will occur regardless of this setting. |
@ahuynhMITRE Can you get a definitive answer from Microsoft support team on the impact of the change and whether custom scripting will still be available in SharePoint or not? |
Met with @tkol2022 and @mitchelbaker-cisa on 04/15 to discuss and level set. Below are the actions and decisions made:
|
For the new issue related to bullet 1, name the issue "Develop and test custom scripting exploit to perform impact analysis of Sharepoint section 4 policies" and label the issue as handsonprototyping. The general scope would be to write a custom script that simulates a malicious action like downloading a set of files. Using test accounts we can simulate a phishing attack to lure a target user to click on a Sharepoint link that will execute the script within the context of the target user's identity. |
💡 Summary
Microsoft is making updates to the custom scripting configuration options for Sharepoint and OneDrive in March 2024. The purpose of this issue is to determine if we need to remove or revise policies MS.SHAREPOINT.4.1v1 and 4.2 based on the changes.
https://techcommunity.microsoft.com/t5/sharepoint/removing-custom-scripting-on-sharepoint-sites/m-p/4055563
Implementation notes
The text was updated successfully, but these errors were encountered: