Cloud Management Gateway - 'HTTP Strict Transport Security' not set on CMG VM

Delroy McKenzie (IT Services) 26 Reputation points
2020-10-29T17:16:06.913+00:00

Hi Support,

It has been flagged by our security team that the Azure VM provisioned as part of the Cloud Management Gateway does not have 'HTTP Strict Transport Security' (HSTS) set. This has been flagged as a vulnerability.

How do we go about mitigating this?

Regards.

Microsoft Configuration Manager Updates
Microsoft Configuration Manager Updates
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Updates: Broadly released fixes addressing specific issue(s) or related bug(s). Updates may also include new or modified features (i.e. changing default behavior).
1,005 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Jason Sandys 31,186 Reputation points Microsoft Employee
    2020-10-30T13:56:54.14+00:00

    As the CMG is a managed service, there is no supported way for you to deal with this. You should do one (or all) of the following:

    • File an item using the in-console feedback system
    • File a UserVoice item
    • Open a support case
    1 person found this answer helpful.
    0 comments No comments