How to disable the X-Powered-By HTTP header in Microsoft IIS - WKB202337
Article number: 202337
OBJECTIVE or GOAL
Prevent IIS from sending the X-Powered-By header in HTTP/S responses.
ENVIRONMENT
- Windows Server 2019/2016/2012
PROCEDURE
- Open IIS Manager.
- Connect to the local server
- Select the Default Web Site.
- Double-click HTTP Response Headers.
- Select X-Powered-By.
- Click Remove.
- Click Yes when prompted to confirm the change.
- For NuGenesis versions 9.1+: Repeat steps 4 through 7 for the two sites "AuditTrailClientApp" and "AuditTrailWebServer".
- Click on the local server entry.
- Double-click Configuration Editor.
- Select the section "system.webServer/proxy".
- Set "arrResponseHeader" to False.
- Click Apply.
- Restart the web server.
ADDITIONAL INFORMATION
See article 202467 for guidance on determining if the header is no longer present in the HTTP replies from the server.
id202337, SUPNG