Content-Security-Policy can be used to help detect and mitigate certain types of attacks. Whilst enabling this across 365, we could also do with making it easy for customers to amend the CSP to include any content that they themselves have included on a page (eg javascript frameworks hosted on other sites).