Skip to main content
Sitecore Documentation
  • Learn
  • Downloads
  • Changelog
  • Roadmap
XP
Platform Administration and Architecture
    • Securing Experience Manager
    • Securing Experience Platform
        • Database security recommendations
        • Configure SQL Always Encrypted for the xDB Collection database
        • Walkthrough: Configuring Always Encrypted for the Sitecore Cortex Processing databases using Azure Key Vault
        • Walkthrough: Configuring Always Encrypted for the Sitecore Cortex Processing databases using Windows Key Store
        • Walkthrough: Setting up Always Encrypted for the suppression list in EXM
        • Allow or deny users access to web resources
        • Change the administrator password
        • Change the hash algorithm for password encryption
        • Configure API authentication keys in a scaled environment
        • Configuring your firewall
        • Enable and disable an administrative tool
        • Disable client RSS feeds
        • Disable SQL Server access from XSLT
        • Enable or disable client certificate authentication for XP service roles
        • Replace a Sitecore client certificate in Azure
        • Enable FIPS
        • Increase login security
        • IP hashing
        • Limit access to XML, XSLT, and MRT files
        • Limit access to PhantomJS
        • Protect media requests
        • Remove header information from responses sent by your website
        • Restrict access to the client
        • Secure Sitecore.Services.Client
        • Secure the file upload functionality
        • Secure the Telerik controls
        • Separate Content Management and Content Delivery servers
        • Enforce a strong password policy
        • Protect the connection string passwords from unauthorized access
        • Updates and disaster recovery
    • Application and database permissions
  1. Security guide
  1. Platform Administration and Architecture
  2. Security guide
  3. Security tasks

Security tasks

Version:

This section lists all security hardening and security configuration tasks in no particular order. Each topic includes information about which role is affected.

Refer to the following topics for a list of security tasks organized by role:

  • Securing Experience Manager

  • Securing Experience Platform

Security tasks

  • Change the administrator password

  • Configure API authentication keys in a scaled environment

  • Disable administrative tools

  • Disable client RSS feeds

  • Disable SQL Server access from XSLT

  • Enable client certificate authentication

  • Enable FIPS

  • Enforce HTTPS for XP service roles

  • Enable HTTPS for core roles

  • Enable HTTPS for Content Search

  • Enforce HTTPS for xConnect Search

  • Enforce HTTPS for the xDB Processing service end point

  • Enable HTTPS for the Content Publishing role

  • Increase login security

  • Limit access to .XML, .XSLT, and .MRT files

  • Change the hash algorithm for password encryption

  • Protect media requests

  • Remove header information from responses sent by your website

  • Restrict access to the client

  • Secure the file upload functionality

  • Limit access to PhantomJS

  • Secure Sitecore.Services.Client

  • Secure the Telerik controls

  • IP hashing

  • Separate Content Management and Content Delivery servers

  • Configure SQL Always Encrypted for the xDB Collection database

If you have suggestions for improving this article, let us know!

Documentation Assistant

This assistant uses AI to generate responses based on Sitecore documentation. While it has access to official sources, answers may be incomplete or inaccurate and should not be considered official advice or support.
Powered by
k
kapa.ai
Protected by reCAPTCHA

© Copyright 2026, Sitecore A/S or a Sitecore affiliated company.
All rights reserved.

Privacy policySitecore Trust CenterTerms of use