locked
Skype for bushiness Server Hardening IIS header RRS feed

  • Question

  • Hello , 

    My security team wishes me to do the follow on my Skype for bushiness servers  *( 1 Pool  with 3 enterprise FE server , Edge, Proxy and Pchat )  

    1. Configure X-FRAME-OPTIONS Header.

    https://developer.mozilla.org/en-US/docs/Web/HTTP/X-Frame-Options

    2.Configure X-Content-Type Header

    https://kb.sucuri.net/warnings/hardening/headers-x-content-type

    3.Configure X-XSS-Protection Header.

    https://kb.sucuri.net/warnings/hardening/headers-x-xss-protection

    4.Disable response headers containing version information. (eg Server:,X-AspNet-Version:,X-AspNetMvc-Version:)

    https://technet.microsoft.com/en-us/library/cc733102(v=ws.10).aspx


    Will modifying any these header , Cause issue and if not is there any supporting documentation on how to do so (web.config files  to modify )   


    Dean 

    Wednesday, September 14, 2016 1:31 PM

Answers

  • Hi Dean,

    Welcome to our forum.

    This is an issue about skype for business. For solving this issue as soon as possible, we suggest you repost this case to the following forum:

    https://social.msdn.microsoft.com/Forums/en-US/home?category=SfB 

    The reason why we recommend posting appropriately is you will get the most qualified pool of respondents, and other partners who read the forums regularly can either share their knowledge or learn from your interaction with us. Thank you for your understanding.

    Notice: We will add Microsoft recommend we didn’t do any modify on hardening IIS in Skype for business server, Microsoft will be out of support if there are some corrupt after we modify it.

    Best Regard,
    Jim Xu
    TechNet Community Support


    Please remember to mark the replies as answers if they help and unmark them if they provide no help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    • Proposed as answer by jim-xu Monday, September 19, 2016 9:53 AM
    • Marked as answer by jim-xu Monday, September 26, 2016 4:49 AM
    Thursday, September 15, 2016 6:04 AM