How to Disable DenyAddAndCustomizePages for a Specific SharePoint Site
Question details
The user needs to upload JavaScript files to a specific SharePoint site for a Microsoft 365-hosted application, but the action is blocked by the DenyAddAndCustomizePages policy.

- Product
- Microsoft SharePoint
- Device & OS
- not provided
- Scenario
- Attempting to run custom scripts or upload JavaScript files to a specific SharePoint site URL for an integrated application.
- Observed behavior
- The DenyAddAndCustomizePages policy prevents the custom scripts from running, and attempts by the user to locate the tenant administrator via the Microsoft 365 Message Center resulted in an error.
Before attempting to modify SharePoint security policies, confirm that you have Microsoft 365 Global Administrator or SharePoint Administrator privileges, and carefully evaluate the security risks of allowing custom scripts on your site.
Contact Your Organization's Tenant Administrator
If your account does not have tenant administrator privileges, you cannot disable this policy yourself and must request the change through official IT support channels.
The DenyAddAndCustomizePages policy is strictly controlled by SharePoint and Microsoft 365 administrators to protect organizational data from malicious scripts.
Do not rely on the Message Center in the Microsoft 365 admin center to identify your administrator, as standard users often receive access errors when attempting this.
Instead of using the Microsoft 365 Admin Center, reach out to your company's IT helpdesk or internal support portal to identify the active SharePoint administrator.
Provide your IT team with the specific SharePoint site URL and explain that your Microsoft 365-hosted application requires uploading JavaScript files, which necessitates modifying the custom-script policy.
Allow the administration team to review the security impact and Microsoft guidance before they implement any changes to the DenyAddAndCustomizePages setting.
Verify Admin Roles and Review Microsoft Guidance
For users who believe they should have administrative access, verify your current roles before attempting to run PowerShell commands to change the script policy.
Looking for a seamless Office alternative? Try WPS Office
While WPS Office cannot change Microsoft SharePoint admin policies, it provides a lightweight, highly compatible alternative for managing your daily documents, spreadsheets, and presentations without complex tenant configurations.
- 1. Download the installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install the software: Run the downloaded installer file and follow the on-screen instructions to complete the setup.
- 3. Open and edit documents seamlessly: Launch WPS Office to easily open, edit, and save your existing Microsoft Office files without formatting issues.

Frequently Asked Questions
Why do I get an error when looking for the tenant admin in the Message Center?
The Message Center within the Microsoft 365 admin center is designed for administrative alerts, not as a directory for end-users to find IT staff. If your account lacks administrative permissions, accessing it will result in an error. Always use your company's internal IT support system instead.
What is the DenyAddAndCustomizePages policy in SharePoint?
It is a security feature in SharePoint Online that prevents users from running custom scripts (like JavaScript) or heavily modifying pages. It is enabled by default to protect the tenant from potentially malicious code and security vulnerabilities.
Can I run custom JavaScript on my SharePoint site without disabling this policy?
Generally, no. If your application specifically requires uploading and executing custom .js files directly on the site pages, the custom script policy must be adjusted. Alternatively, developers can use the modern SharePoint Framework (SPFx), which is the Microsoft-recommended way to deploy custom code without disabling security policies.
Will enabling custom scripts affect my SharePoint site's security?
Yes. Allowing custom scripts increases security risks by permitting code execution on the site. Administrators are advised to review Microsoft's security guidance and limit this change to specific, trusted sites rather than enabling it across the entire tenant.




