web
You’re offline. This is a read only version of the page.
close
Skip to main content
Community site session details

Community site session details

Session Id :
Finance | Project Operations, Human Resources, ...
Answered

How to prevent Cross-Site Request Forgery on D365FF0 on-premises that is exposed over the internet ?

(0) ShareShare
ReportReport
Posted on by 90

Hi All,

we have a client that did a test and found the below outputs and want us to fix them before going live, any D365FFO on-premises security expert may help us on the below output especially the Cross-Site Request Forgery

Finding

Severity

Cross-Site Request Forgery

Moderate

Missing or insecure "X-XSS-Protection" header

Low

Missing or insecure Cross-Frame Scripting Defense

Low

Older TLS Version is Supported

Low

SHA-1 cipher suites were detected

Low

I have the same question (0)
  • nmaenpaa Profile Picture
    101,160 Moderator on at
    RE: How to prevent Cross-Site Request Forgery on D365FF0 on-premises that is exposed over the internet ?

    Did your customer share any more details about their analysis than this list? Perhaps if we could see how they came into that conclusion it would be easier to comment on it.

  • MDeeb Profile Picture
    90 on at
    RE: How to prevent Cross-Site Request Forgery on D365FF0 on-premises that is exposed over the internet ?

    Thank you nikolaos,

    no they only shared this table with us.

    Regards,

  • nmaenpaa Profile Picture
    101,160 Moderator on at
    RE: How to prevent Cross-Site Request Forgery on D365FF0 on-premises that is exposed over the internet ?

    Then I suggest asking them for more details. You want to know what the problem is before you start solving it. 

  • Verified answer
    nmaenpaa Profile Picture
    101,160 Moderator on at
    RE: How to prevent Cross-Site Request Forgery on D365FF0 on-premises that is exposed over the internet ?

    Also please remember that you can't control the architecture of D365FO itself - so if these comments are related to the application itself, how it handles logins, sessions and security, there's not much you or your customer can do.

    And if they have hard requirements on such areas, they should actually evaluate them before choosing the ERP system, not just before golive :)

  • MDeeb Profile Picture
    90 on at
    RE: How to prevent Cross-Site Request Forgery on D365FF0 on-premises that is exposed over the internet ?

    Thank you Nikolaos,

    i've asked the client for details and will revert back once i get them.

    Thanks a lot.

  • MDeeb Profile Picture
    90 on at
    RE: How to prevent Cross-Site Request Forgery on D365FF0 on-premises that is exposed over the internet ?

    Thanks Nikolaos,

    The customer has agreed on it.

    Thanks for your usual help.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Pallavi Phade – Community Spotlight

We are honored to recognize Pallavi Phade as our Community Spotlight honoree for…

Leaderboard > Finance | Project Operations, Human Resources, AX, GP, SL

#1
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 734 Super User 2025 Season 2

#2
CA Neeraj Kumar Profile Picture

CA Neeraj Kumar 636

#3
Martin Dráb Profile Picture

Martin Dráb 553 Most Valuable Professional

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans