Description
A Web App that permits older TLS versions may not meet organizational transport security requirements. App Service uses TLS 1.2 as the minimum for new apps and also supports TLS 1.3. An omitted configuration value does not by itself establish that older protocols are allowed; check the effective setting.
Set the minimum through the site's siteConfig.minTlsVersion or minTlsVersion in its web child configuration. TLS settings for the app and SCM administration site, and HTTPS use, are separate controls to review together.
Potential impact
- Permitted legacy TLS connections may fail security requirements or retain risks associated with older cryptographic methods.
- Raising the minimum without compatibility checks can interrupt required clients or deployment tools.
Remediation
Explicitly set a supported minimum of 1.2 or later, and consider 1.3 where clients support it. Review the effective app and SCM settings, then test allowed connections and rejection of older protocols. Manage certificate validation, cipher suites, and HTTPS use as well.
Examples
These excerpts show an app and its web child configuration. Supply the actual app name, App Service plan, and other deployment inputs separately.
Before
resource app 'Microsoft.Web/sites@2022-09-01' = {
name: 'example-app'
location: resourceGroup().location
properties: {}
}
resource appWebConfig 'Microsoft.Web/sites/config@2022-09-01' = {
parent: app
name: 'web'
properties: {
minTlsVersion: '1.1'
}
}
This specifies a minimum of 1.1. Check the environment's supported protocol policy and actual negotiation results.
After
resource app 'Microsoft.Web/sites@2022-09-01' = {
name: 'example-app'
location: resourceGroup().location
properties: {}
}
resource appWebConfig 'Microsoft.Web/sites/config@2022-09-01' = {
parent: app
name: 'web'
properties: {
minTlsVersion: '1.2'
}
}
This sets 1.2 in the same child configuration. It does not also configure the SCM minimum TLS version or HTTP redirection.