Troubleshooting: URLScan Conflicts with IIS on Windows Server 2016 and Later

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All

     

    Overview

    On Windows Server 2016 and later, having URLScan installed alongside SecureAuth causes conflicts with IIS Request Filtering and URL Rewrite rules.

     

    Cause

    URLScan was commonly installed on older versions of Windows Server to protect against malicious URLs or HTTP request methods sent to a web server. Starting with Windows Server 2016, this same functionality is already built into IIS as Request Filtering. Having URLScan installed alongside Windows Server 2016's built-in Request Filtering causes the two to conflict, which can also interfere with the URL Rewrite rules applied to the IIS server.

     

    Resolution

    Uninstall URLScan from any server running Windows Server 2016 or later.

     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.