X-Frame-Options on Exchange 2019

Dmitriy Rakhmanin 1 Reputation point
2021-12-05T12:35:22.02+00:00

Hello everyone.
I'm trying to add X-Frame-Options header on Exchange server's IIS.
Added it in Default Web Site's and Exchange Back End's HTTP Response Headers.
Tried to manually add this Header to every subdirectory (such as owa, ecp, etc.).
After every change I've been restarting IIS server.
No success.
During scan with Nikto tool (similar to OWASP zap) it outputs the following string:

  • The anti-clickjacking X-Frame-Options header is not present.

Checked this header in OOS's IIS and other IIS Servers. It works, so problem is somewhere in Exchange's IIS.
Any advises ?

Internet Information Services
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,373 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Kael Yao-MSFT 37,496 Reputation points Microsoft Vendor
    2021-12-06T07:35:01.22+00:00

    Hi @Dmitriy Rakhmanin

    Added it in Default Web Site's and Exchange Back End's HTTP Response Headers.
    Tried to manually add this Header to every subdirectory (such as owa, ecp, etc.).

    Have you tried added the HTTP Response Header to the Default Web Site?
    The subdirectories would inherite this setting.
    155223-05.png


    After the configuration, can you see this header via browser?
    155231-08.png

    If it is present, the header should have been added successfully.


    To confirm it, you may also Enable Failed-Request Tracing in IIS.

    Under the Compact View tag of the xml files, please look for the GENERAL_SET_RESPONSE_HEADER event.
    If you can see this event, the header should have been added successfully.
    155194-09.png


    If it still fails the test, please restart the Exchange server and see if it can help with this issue.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.