---
title: Secure cookies by default
description: Configure PingAM to mark cookies as secure so they transmit only over HTTPS, protecting sessions from HTTP redirection attacks
component: pingam
version: 7.5
page_id: pingam:security:configuring-secure-cookies
canonical_url: https://docs.pingidentity.com/pingam/8.1/security/configuring-secure-cookies.html
llms_txt: https://docs.pingidentity.com/pingam/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
keywords: ["Security", "Setup &amp; Configuration"]
page_aliases: ["security-guide:configuring-secure-cookies.adoc"]
superseded_by: https://docs.pingidentity.com/pingam/8.1/security/configuring-secure-cookies.html
---

# Secure cookies by default

When using HTTPS, mark all your cookies as secure, which means they are only transmitted over HTTPS protocols.

This flag is useful for sites that allow both HTTPS and HTTP traffic, since it protects from HTTP redirection carrying session cookies across unencrypted connections.

1. In the AM admin UI, go to Configure > Server Defaults > Security > Cookie.

2. Enable the Secure Cookie option.

3. Click Save Changes.

4. Restart AM or the container where it runs.
