Review the Web App minimum TLS version

Review the effective App Service minimum TLS version and client compatibility, and use TLS 1.2 or later.

Description

A Web App that permits older TLS versions may not meet organizational transport security requirements. App Service uses TLS 1.2 as the minimum for new apps and also supports TLS 1.3. An omitted configuration value does not by itself establish that older protocols are allowed; check the effective setting.

Set the minimum through the site's siteConfig.minTlsVersion or minTlsVersion in its web child configuration. TLS settings for the app and SCM administration site, and HTTPS use, are separate controls to review together.

Potential impact

  • Permitted legacy TLS connections may fail security requirements or retain risks associated with older cryptographic methods.
  • Raising the minimum without compatibility checks can interrupt required clients or deployment tools.

Remediation

Explicitly set a supported minimum of 1.2 or later, and consider 1.3 where clients support it. Review the effective app and SCM settings, then test allowed connections and rejection of older protocols. Manage certificate validation, cipher suites, and HTTPS use as well.

Examples

These excerpts show an app and its web child configuration. Supply the actual app name, App Service plan, and other deployment inputs separately.

Before

bicep
resource app 'Microsoft.Web/sites@2022-09-01' = {
  name: 'example-app'
  location: resourceGroup().location
  properties: {}
}

resource appWebConfig 'Microsoft.Web/sites/config@2022-09-01' = {
  parent: app
  name: 'web'
  properties: {
    minTlsVersion: '1.1'
  }
}

This specifies a minimum of 1.1. Check the environment's supported protocol policy and actual negotiation results.

After

bicep
resource app 'Microsoft.Web/sites@2022-09-01' = {
  name: 'example-app'
  location: resourceGroup().location
  properties: {}
}

resource appWebConfig 'Microsoft.Web/sites/config@2022-09-01' = {
  parent: app
  name: 'web'
  properties: {
    minTlsVersion: '1.2'
  }
}

This sets 1.2 in the same child configuration. It does not also configure the SCM minimum TLS version or HTTP redirection.

References