Review App Service HTTP/2 settings

Review App Service HTTP/2 compatibility and performance needs, and manage HTTPS and TLS separately.

Description

Azure App Service uses siteConfig.http20Enabled to control HTTP/2 support. HTTP/2 can handle multiple requests efficiently over one connection, helping application performance and connection efficiency.

Not using HTTP/2 is not itself a security vulnerability. Review HTTP/2 support separately from HTTPS enforcement, TLS versions and authentication.

Potential impact

  • An application may miss HTTP/2 performance benefits, depending on its workload and clients.
  • Inconsistent service settings can complicate operational policy management.

Remediation

  • Check application and client compatibility, and set siteConfig.http20Enabled: true when HTTP/2 is required.
  • Check custom proxy and middleware constraints, then verify the negotiated protocol and response performance. Maintain HTTPS and TLS protection separately.

Examples

These excerpts show selected App Service properties. The service plan and other application settings required for deployment are omitted. Both retain httpsOnly: true.

Before

bicep
resource webApp 'Microsoft.Web/sites@2020-12-01' = {
  name: 'example-webapp'
  location: resourceGroup().location
  properties: {
    httpsOnly: true
  }
}

HTTP/2 is not explicitly configured. Check the effective settings and protocol in use.

After

bicep
resource webApp 'Microsoft.Web/sites@2020-12-01' = {
  name: 'example-webapp'
  location: resourceGroup().location
  properties: {
    httpsOnly: true
    siteConfig: {
      http20Enabled: true
    }
  }
}

HTTP/2 is explicitly enabled. This alone does not guarantee that every client uses HTTP/2 or that performance improves.

References