Description
Azure App Service uses siteConfig.http20Enabled to control HTTP/2 support. HTTP/2 can handle multiple requests efficiently over one connection, helping application performance and connection efficiency.
Not using HTTP/2 is not itself a security vulnerability. Review HTTP/2 support separately from HTTPS enforcement, TLS versions and authentication.
Potential impact
- An application may miss HTTP/2 performance benefits, depending on its workload and clients.
- Inconsistent service settings can complicate operational policy management.
Remediation
- Check application and client compatibility, and set
siteConfig.http20Enabled: truewhen HTTP/2 is required. - Check custom proxy and middleware constraints, then verify the negotiated protocol and response performance. Maintain HTTPS and TLS protection separately.
Examples
These excerpts show selected App Service properties. The service plan and other application settings required for deployment are omitted. Both retain httpsOnly: true.
Before
resource webApp 'Microsoft.Web/sites@2020-12-01' = {
name: 'example-webapp'
location: resourceGroup().location
properties: {
httpsOnly: true
}
}
HTTP/2 is not explicitly configured. Check the effective settings and protocol in use.
After
resource webApp 'Microsoft.Web/sites@2020-12-01' = {
name: 'example-webapp'
location: resourceGroup().location
properties: {
httpsOnly: true
siteConfig: {
http20Enabled: true
}
}
}
HTTP/2 is explicitly enabled. This alone does not guarantee that every client uses HTTP/2 or that performance improves.