HSTS on ADFS

BRYAN BURNETT 16 Reputation points
2020-09-22T19:52:00.9+00:00

We're running ADFS on Windows Server 2019, with the appropriate headers enabled. Much like this prior question, we need to have ADFS return a header, showing HSTS enabled, rather than a 404, if the root is called -- i.e., https://adfs.url.com. HSTS shows as enabled for a valid endpoint, such as https://adfs.url.com/adfs/ls/IdpInitiatedSignon.aspx, but our vulnerability auditors insist on calling the root. Any ideas?

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,247 questions
{count} votes

1 answer

Sort by: Most helpful
  1. 9704244848 186 Reputation points
    2020-09-24T16:42:37.317+00:00

    I had the same issue/question for few weeks - Configure HSTS for AD FS
    There is no way to modify the behavior. Work as designed by microsoft.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.