Review App Service built-in authentication

Apply appropriate authentication and authorization to protected paths.

Description

App Service built-in authentication can authenticate users before requests reach the app. An application can also implement its own authentication, so disabling the built-in feature does not itself establish anonymous public access. Check actual access controls for administration apps and internal tools.

Potential impact

Without authentication and authorization on protected paths, unauthorized users may access data or functions.

Remediation

When using built-in authentication, enable auth_settings.enabled or auth_settings_v2.auth_enabled and configure an identity provider. Require authentication on protected paths, set the handling of anonymous requests, and validate required user or role permissions. Review public paths and apps with their own authentication according to their design.

Examples

These are legacy azurerm_app_service excerpts for AzureRM 3.x. Use the Linux or Windows Web App resources for current configurations and supply omitted settings such as the identity provider.

Before

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
  }

  app_settings = {
    "SOME_KEY" = "some-value"
  }
}

After

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
  }

  app_settings = {
    "SOME_KEY" = "some-value"
  }

  auth_settings {
    enabled = true
  }
}

The second excerpt enables the built-in feature. That option alone does not reject every anonymous request; test unauthenticated and unauthorized requests separately.

References