web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Pages / Implement HTTP Strict ...
Power Pages
Unanswered

Implement HTTP Strict transport security header Portal

(0) ShareShare
ReportReport
Posted on by 57

Hi Guys,

 

In one of the security scan reports, there are two vulnerability findings from the portal - 

1. HTTP Strict Transport Security (HSTS) header is not configured (Remediation mentioned - It is recommended to implement HTTP Strict-Transport-Security response header which will let the web site tell browsers that it should only be accessed using HTTPS, instead of using HTTP.)

2. Cache-Control Header not properly configured (Remediation mentioned - Set the Cache-control response header to "no-cache, no-store, expires 0" on all responses.)

 

Can you kindly let me know how to enable these settings in Power Portal. Attaching screenshots from browser Network tool for better reference.

@OOlashyn @ragavanrajan @OliverRodrigues 

Categories:
I have the same question (0)
  • OOlashyn Profile Picture
    3,496 Most Valuable Professional on at

    Hi @Pruss10,

    Can you open a ticket with MS and share your findings from security scan report? I hope that will help MS to mitigate those issues from their end. Meanwhile, as a workaround you can use Head/Bottom content snippet that is added at the end of the head tag of all pages. You can set Cache-Control via meta tag (you should be able to do this with HSTS as well but I never tried it):

    <meta http-equiv="Cache-control" content="no-cache">

     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Power Pages

#1
Jerry-IN Profile Picture

Jerry-IN 71

#2
Fubar Profile Picture

Fubar 62 Super User 2025 Season 2

#3
sannavajjala87 Profile Picture

sannavajjala87 31

Last 30 days Overall leaderboard