Description
Without App Service platform authentication, the application must enforce the authentication and permissions it needs. An internal API or administration path without adequate authentication can process unauthorized requests. Application-level authentication and intentionally public paths are also valid designs, so disabling the platform feature alone does not establish anonymous access.
Enabling platform authentication can still allow anonymous requests, depending on policy. Configure the identity provider, unauthenticated-request behavior, and user permissions together.
Potential impact
- Unprotected paths that require authentication can permit unauthorized data access or administration.
- Authenticated users with excessive permissions can perform actions beyond their business role.
Remediation
Define which paths require platform or suitable application-level authentication. When using platform authentication, configure the provider and rejection or sign-in behavior for unauthenticated requests, and restrict allowed users and actions. Apply HTTPS and necessary network restrictions, then test anonymous and authenticated requests separately.
Examples
These authsettings excerpts use an existing webApp1 parent. Provider and user policies are omitted.
Before
resource webApp1_authsettings 'Microsoft.Web/sites/config@2020-12-01' = {
parent: webApp1
name: 'authsettings'
properties: {
enabled: false
}
}
This disables platform authentication. Review the application's own authentication and effective access policies separately.
After
resource webApp1_authsettings 'Microsoft.Web/sites/config@2020-12-01' = {
parent: webApp1
name: 'authsettings'
properties: {
enabled: true
}
}
This enables the platform authentication feature. The value alone does not reject anonymous requests; also configure the provider and unauthenticated-request policy.