Other Configuration Manager-related features and issues
SCCM EHTTP and IIS HSTS Guidance
Hello Microsoft Support Team,
We are currently using Enhanced HTTP (EHTTP) configuration in our SCCM environment. During a recent Tenable vulnerability scan, a finding was reported that suggested enabling the HSTS protocol on IIS to improve security posture. However, we are concerned that enabling HSTS while EHTTP is in use may cause disruptions such as clients being unable to access policies, OSD task sequences failing, and agents losing connection to the Management Point (MP). Specifically, is enabling HSTS on IIS supported while EHTTP is active, or should it only be considered after transitioning to a full HTTPS/PKI configuration? We want to ensure both compliance with vulnerability management requirements and the continuity of our SCCM environment. Your guidance and help would be greatly appreciated.
We await your urgent response regarding this matter.
Thank you,
Nihat.