How to disable the Server HTTP header in Microsoft IIS - WKB202501
Article number: 202501
OBJECTIVE or GOAL
Prevent IIS from sending the Server header in HTTP/S responses.
ENVIRONMENT
- Windows Server 2019/2016
- Microsoft IIS 10.0+
PROCEDURE
- Open IIS Manager.
- Connect to the local server.
- Select the Default Web Site.
- Double-click the Configuration Editor.
- In the Section list, select system.webServer > security > requestFiltering.
- Set the value of "removeServerHeader" to True.
- Click the Apply button.
- For NuGenesis versions 9.1+: Repeat steps 4 through 7 for the two sites "AuditTrailClientApp" and "AuditTrailWebServer".
- Restart the web server.
ADDITIONAL INFORMATION
See article 202467 for guidance on determining if the header is no longer present in the HTTP replies from the server.
id202501,