SCCM EHTTP and IIS HSTS Guidance

Nihat Elibüyük 0 Reputation points
2026-06-26T07:56:25.39+00:00

Hello Microsoft Support Team,

We are currently using Enhanced HTTP (EHTTP) configuration in our SCCM environment. During a recent Tenable vulnerability scan, a finding was reported that suggested enabling the HSTS protocol on IIS to improve security posture. However, we are concerned that enabling HSTS while EHTTP is in use may cause disruptions such as clients being unable to access policies, OSD task sequences failing, and agents losing connection to the Management Point (MP). Specifically, is enabling HSTS on IIS supported while EHTTP is active, or should it only be considered after transitioning to a full HTTPS/PKI configuration? We want to ensure both compliance with vulnerability management requirements and the continuity of our SCCM environment. Your guidance and help would be greatly appreciated.

We await your urgent response regarding this matter.

Thank you,

Nihat.

Microsoft Security | Intune | Configuration Manager | Other
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.