logo
search
SharePoint Document Issues

How to Disable DenyAddAndCustomizePages for a Specific SharePoint Site

Ayan MasoodAyan Masood Sep 25, 2026 869 views

Question details

The user needs to upload JavaScript files to a specific SharePoint site for a Microsoft 365-hosted application, but the action is blocked by the DenyAddAndCustomizePages policy.

How to Disable DenyAddAndCustomizePages for a Specific SharePoint Site
Product
Microsoft SharePoint
Device & OS
not provided
Scenario
Attempting to run custom scripts or upload JavaScript files to a specific SharePoint site URL for an integrated application.
Observed behavior
The DenyAddAndCustomizePages policy prevents the custom scripts from running, and attempts by the user to locate the tenant administrator via the Microsoft 365 Message Center resulted in an error.
Before you start

Before attempting to modify SharePoint security policies, confirm that you have Microsoft 365 Global Administrator or SharePoint Administrator privileges, and carefully evaluate the security risks of allowing custom scripts on your site.

Solution 1Recommended

Contact Your Organization's Tenant Administrator

If your account does not have tenant administrator privileges, you cannot disable this policy yourself and must request the change through official IT support channels.

The DenyAddAndCustomizePages policy is strictly controlled by SharePoint and Microsoft 365 administrators to protect organizational data from malicious scripts.

Do not rely on the Message Center in the Microsoft 365 admin center to identify your administrator, as standard users often receive access errors when attempting this.

1
Use internal IT support channels

Instead of using the Microsoft 365 Admin Center, reach out to your company's IT helpdesk or internal support portal to identify the active SharePoint administrator.

2
Submit a formal policy change request

Provide your IT team with the specific SharePoint site URL and explain that your Microsoft 365-hosted application requires uploading JavaScript files, which necessitates modifying the custom-script policy.

3
Await security review

Allow the administration team to review the security impact and Microsoft guidance before they implement any changes to the DenyAddAndCustomizePages setting.

Security Impact: Disabling this policy allows executable scripts to run on the site. Administrators must weigh the functionality requirements of your application against the organization's security baseline.
Free Microsoft Office alternative

Looking for a seamless Office alternative? Try WPS Office

While WPS Office cannot change Microsoft SharePoint admin policies, it provides a lightweight, highly compatible alternative for managing your daily documents, spreadsheets, and presentations without complex tenant configurations.

  1. 1. Download the installer: Visit the official WPS Office website and click the free download button for your operating system.
  2. 2. Install the software: Run the downloaded installer file and follow the on-screen instructions to complete the setup.
  3. 3. Open and edit documents seamlessly: Launch WPS Office to easily open, edit, and save your existing Microsoft Office files without formatting issues.
Fully compatible with Microsoft Office formats including .docx, .xlsx, and .pptxLightweight installation that doesn't rely on complex tenant administrative policiesFree to use with a familiar, user-friendly interfaceEasy local and cloud file management for seamless productivity
microsoft office alternative - wps office

Frequently Asked Questions

Why do I get an error when looking for the tenant admin in the Message Center?

The Message Center within the Microsoft 365 admin center is designed for administrative alerts, not as a directory for end-users to find IT staff. If your account lacks administrative permissions, accessing it will result in an error. Always use your company's internal IT support system instead.

What is the DenyAddAndCustomizePages policy in SharePoint?

It is a security feature in SharePoint Online that prevents users from running custom scripts (like JavaScript) or heavily modifying pages. It is enabled by default to protect the tenant from potentially malicious code and security vulnerabilities.

Can I run custom JavaScript on my SharePoint site without disabling this policy?

Generally, no. If your application specifically requires uploading and executing custom .js files directly on the site pages, the custom script policy must be adjusted. Alternatively, developers can use the modern SharePoint Framework (SPFx), which is the Microsoft-recommended way to deploy custom code without disabling security policies.

Will enabling custom scripts affect my SharePoint site's security?

Yes. Allowing custom scripts increases security risks by permitting code execution on the site. Administrators are advised to review Microsoft's security guidance and limit this change to specific, trusted sites rather than enabling it across the entire tenant.