<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Secure Flag on Cookies - Understanding Findings from Third‑Party Security Assessments in Troubleshooting</title>
    <link>https://community.dynatrace.com/t5/Troubleshooting/Secure-Flag-on-Cookies-Understanding-Findings-from-Third-Party/ta-p/293858</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;Customers often contact us after receiving &lt;STRONG&gt;security reports from third‑party assessments or penetration tests&lt;/STRONG&gt; indicating missing &lt;EM&gt;Secure&lt;/EM&gt; attributes on certain cookies.&lt;BR /&gt;This may raise questions about whether the flag should be &lt;STRONG&gt;enabled&lt;/STRONG&gt;, whether it is safe, or whether it can be configured by default across your Dynatrace environment.&lt;/P&gt;
&lt;P&gt;In Dynatrace, the current behavior is &lt;STRONG&gt;by design&lt;/STRONG&gt;:&lt;BR /&gt;The Secure attribute is enabled when technically safe across all HTTPS‑based communication.&lt;BR /&gt;Where it is not yet enforced by default, Dynatrace gradually aligns these cases with modern security best practices.&lt;BR /&gt;When needed, customers can enable the Secure flag according to the official documentation:&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_right:"&gt;👉&lt;/span&gt;&lt;A href="https://docs.dynatrace.com/docs/shortlink/cookies#secure-cookies" target="_blank" rel="noopener"&gt;https://docs.dynatrace.com/docs/shortlink/cookies#secure-cookies&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Enabling the Secure flag is fully supported and recommended in any environment served exclusively over HTTPS. It can also help resolve scanner findings and is supported and recommended if the monitored application is served via HTTPS.&lt;/P&gt;
&lt;DIV&gt;
&lt;H2&gt;&lt;STRONG&gt;Frequently Asked Questions&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Why do scanners report this as a vulnerability?&lt;/STRONG&gt;&lt;BR /&gt;Most security tools follow strict baseline rules (e.g., OWASP). Even if your application already uses HTTPS, scanners will still flag any cookie missing the Secure attribute because they cannot detect context.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Is enabling the Secure flag supported by Dynatrace?&lt;/STRONG&gt;&lt;BR /&gt;Yes. Dynatrace fully supports enabling the Secure flag for its cookies in HTTPS environments.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Will enabling the Secure flag break anything?&lt;/STRONG&gt;&lt;BR /&gt;No. Since Dynatrace traffic is already HTTPS‑based, setting the flag to &lt;EM&gt;Secure = Yes&lt;/EM&gt; does not change behavior, compatibility, or data collection.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can we enable the Secure flag in bulk?&lt;/STRONG&gt;&lt;BR /&gt;Bulk configuration is not currently available on cookie‑level attributes.&lt;BR /&gt;Dynatrace applies secure defaults progressively and allows enabling Secure where applicable through configuration.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can we change the system‑wide default to “Secure = Yes”?&lt;/STRONG&gt;&lt;BR /&gt;Not globally.&lt;BR /&gt;Defaults are applied only where technically safe and aligned with existing architecture.&lt;BR /&gt;Remaining cases are being aligned over time.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Is it safe to enable the Secure flag if everything runs over HTTPS?&lt;/STRONG&gt;&lt;BR /&gt;Absolutely.&lt;BR /&gt;If your environment is HTTPS‑only, enabling the Secure flag is the expected secure configuration and resolves most scanner findings.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Need more help?&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;If you need assistance interpreting your security report or configuring the Secure flag in your environment, feel free to open a ticket with &lt;STRONG&gt;Dynatrace Technical Support&lt;/STRONG&gt; — we’ll be happy to help.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Fri, 30 Jan 2026 11:44:58 GMT</pubDate>
    <dc:creator>LucaGalliani</dc:creator>
    <dc:date>2026-01-30T11:44:58Z</dc:date>
    <item>
      <title>Secure Flag on Cookies - Understanding Findings from Third‑Party Security Assessments</title>
      <link>https://community.dynatrace.com/t5/Troubleshooting/Secure-Flag-on-Cookies-Understanding-Findings-from-Third-Party/ta-p/293858</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;Customers often contact us after receiving &lt;STRONG&gt;security reports from third‑party assessments or penetration tests&lt;/STRONG&gt; indicating missing &lt;EM&gt;Secure&lt;/EM&gt; attributes on certain cookies.&lt;BR /&gt;This may raise questions about whether the flag should be &lt;STRONG&gt;enabled&lt;/STRONG&gt;, whether it is safe, or whether it can be configured by default across your Dynatrace environment.&lt;/P&gt;
&lt;P&gt;In Dynatrace, the current behavior is &lt;STRONG&gt;by design&lt;/STRONG&gt;:&lt;BR /&gt;The Secure attribute is enabled when technically safe across all HTTPS‑based communication.&lt;BR /&gt;Where it is not yet enforced by default, Dynatrace gradually aligns these cases with modern security best practices.&lt;BR /&gt;When needed, customers can enable the Secure flag according to the official documentation:&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_right:"&gt;👉&lt;/span&gt;&lt;A href="https://docs.dynatrace.com/docs/shortlink/cookies#secure-cookies" target="_blank" rel="noopener"&gt;https://docs.dynatrace.com/docs/shortlink/cookies#secure-cookies&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Enabling the Secure flag is fully supported and recommended in any environment served exclusively over HTTPS. It can also help resolve scanner findings and is supported and recommended if the monitored application is served via HTTPS.&lt;/P&gt;
&lt;DIV&gt;
&lt;H2&gt;&lt;STRONG&gt;Frequently Asked Questions&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Why do scanners report this as a vulnerability?&lt;/STRONG&gt;&lt;BR /&gt;Most security tools follow strict baseline rules (e.g., OWASP). Even if your application already uses HTTPS, scanners will still flag any cookie missing the Secure attribute because they cannot detect context.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Is enabling the Secure flag supported by Dynatrace?&lt;/STRONG&gt;&lt;BR /&gt;Yes. Dynatrace fully supports enabling the Secure flag for its cookies in HTTPS environments.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Will enabling the Secure flag break anything?&lt;/STRONG&gt;&lt;BR /&gt;No. Since Dynatrace traffic is already HTTPS‑based, setting the flag to &lt;EM&gt;Secure = Yes&lt;/EM&gt; does not change behavior, compatibility, or data collection.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can we enable the Secure flag in bulk?&lt;/STRONG&gt;&lt;BR /&gt;Bulk configuration is not currently available on cookie‑level attributes.&lt;BR /&gt;Dynatrace applies secure defaults progressively and allows enabling Secure where applicable through configuration.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can we change the system‑wide default to “Secure = Yes”?&lt;/STRONG&gt;&lt;BR /&gt;Not globally.&lt;BR /&gt;Defaults are applied only where technically safe and aligned with existing architecture.&lt;BR /&gt;Remaining cases are being aligned over time.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Is it safe to enable the Secure flag if everything runs over HTTPS?&lt;/STRONG&gt;&lt;BR /&gt;Absolutely.&lt;BR /&gt;If your environment is HTTPS‑only, enabling the Secure flag is the expected secure configuration and resolves most scanner findings.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Need more help?&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;If you need assistance interpreting your security report or configuring the Secure flag in your environment, feel free to open a ticket with &lt;STRONG&gt;Dynatrace Technical Support&lt;/STRONG&gt; — we’ll be happy to help.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 30 Jan 2026 11:44:58 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Troubleshooting/Secure-Flag-on-Cookies-Understanding-Findings-from-Third-Party/ta-p/293858</guid>
      <dc:creator>LucaGalliani</dc:creator>
      <dc:date>2026-01-30T11:44:58Z</dc:date>
    </item>
  </channel>
</rss>

