Review App Service authentication settings

Review App Service and application authentication policies, and restrict anonymous requests to protected paths.

Description

Without App Service platform authentication, the application must enforce the authentication and permissions it needs. An internal API or administration path without adequate authentication can process unauthorized requests. Application-level authentication and intentionally public paths are also valid designs, so disabling the platform feature alone does not establish anonymous access.

Enabling platform authentication can still allow anonymous requests, depending on policy. Configure the identity provider, unauthenticated-request behavior, and user permissions together.

Potential impact

  • Unprotected paths that require authentication can permit unauthorized data access or administration.
  • Authenticated users with excessive permissions can perform actions beyond their business role.

Remediation

Define which paths require platform or suitable application-level authentication. When using platform authentication, configure the provider and rejection or sign-in behavior for unauthenticated requests, and restrict allowed users and actions. Apply HTTPS and necessary network restrictions, then test anonymous and authenticated requests separately.

Examples

These authsettings excerpts use an existing webApp1 parent. Provider and user policies are omitted.

Before

bicep
resource webApp1_authsettings 'Microsoft.Web/sites/config@2020-12-01' = {
  parent: webApp1
  name: 'authsettings'
  properties: {
    enabled: false
  }
}

This disables platform authentication. Review the application's own authentication and effective access policies separately.

After

bicep
resource webApp1_authsettings 'Microsoft.Web/sites/config@2020-12-01' = {
  parent: webApp1
  name: 'authsettings'
  properties: {
    enabled: true
  }
}

This enables the platform authentication feature. The value alone does not reject anonymous requests; also configure the provider and unauthenticated-request policy.

References