How to disable the X-AspNetVersion HTTP header in Microsoft IIS - WKB203642
Article number: 203642
OBJECTIVE or GOAL
Prevent IIS from sending the X-AspNetVersion header in HTTP/S responses.
ENVIRONMENT
- Windows Server 2019/2016/2012
PROCEDURE
- Open IIS Manager.
- Connect to the local server.
- Select the Default Web Site.
- Double-click the Configuration Manager.
- In the Section list, select system.web > httpRuntime.
- Set the value of "enableVersionHeader" to False.
- Click the Apply button.
- Repeat steps 4 through 7 for all HTTP/S sites in IIS and all applications in Default Web Site.
- Restart IIS.
ADDITIONAL INFORMATION
See article 202467 for guidance on determining if the header is no longer present in the HTTP replies from the server.
id203642, SUPNG