Enabling HTTP Strict Transport Security (HSTS)

In newer versions of Internet Information Services (IIS) Manager, administrator can enforce HTTPS to be used and redirect all HTTP requests to HTTPS.

Prerequisites

  • Internet Information Services Manager 10.0 version 1709 or newer.

Note: Enabling HSTS is site-specific.

Do the following:

  1. In IIS Manager, in the Connections pane, under Sites, select the site which settings to modify.

  2. In Actions pane, under Configure, select HSTS. Edit Website HSTS dialog opens.

  3. Select Enable.

  4. Enable Redirect Http to Https.

  5. Select OK to confirm the changes.