What is built into this release
The first delivery slice focuses on the controls that should never be retrofitted.
Secure headers
CSP, HSTS, referrer policy, and permission controls ship with the app.
Server-managed sessions
The portal avoids client token storage and derives access from OIDC sessions.