Enable HSTS on Exchange Server 2019

Mohammed Nadeem 141 Reputation points


We have 3 Exchange server2019 with DAG configured on windows server 2019.

We need to enable to HSTS,

I have setting to configure on Default Web site --> HSTS and enter below entries:

Max-age 31536000

Enable incluseSubDomains

Enable Preload

Is this setting correct and Is there any impect on exchange server for users and DBs ?

Exchange Server
Exchange Server
A family of Microsoft client/server messaging and collaboration software.
723 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
10,626 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
6,853 questions
0 comments No comments
{count} votes

Accepted answer
  1. Jame Xu-MSFT 4,056 Reputation points

    Hi @Mohammed Nadeem ,

    The setting is correct. Refer to: Configure HSTS on Exchange Server

    Configure HSTS on Windows Server 2019 and higher:

    1. Sign in to the Exchange Server and start Internet Information Services (IIS) Manager.

    2. Click in the connections panel on Default Web Site.

    3. Click in the actions panel on HSTS…

    4. Check the checkboxes and fill in the Max-Age: 31536000. Click OK.

    You could check it:

    1. Start your favorite web browser and go to the Exchange Server OWA address.

    2. Open the browser inspector tool > Network.

    3. Click on the refresh button or press F5 to reload the page.

    4. Select the document HTML URL and verify that it shows the header:

    strict-transport-security: max-age=31536000; includeSubDomains; preload

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment". 

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful