Description
App Service built-in authentication can authenticate users before requests reach the app. An application can also implement its own authentication, so disabling the built-in feature does not itself establish anonymous public access. Check actual access controls for administration apps and internal tools.
Potential impact
Without authentication and authorization on protected paths, unauthorized users may access data or functions.
Remediation
When using built-in authentication, enable auth_settings.enabled or auth_settings_v2.auth_enabled and configure an identity provider. Require authentication on protected paths, set the handling of anonymous requests, and validate required user or role permissions. Review public paths and apps with their own authentication according to their design.
Examples
These are legacy azurerm_app_service excerpts for AzureRM 3.x. Use the Linux or Windows Web App resources for current configurations and supply omitted settings such as the identity provider.
Before
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
}
app_settings = {
"SOME_KEY" = "some-value"
}
}
After
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
}
app_settings = {
"SOME_KEY" = "some-value"
}
auth_settings {
enabled = true
}
}
The second excerpt enables the built-in feature. That option alone does not reject every anonymous request; test unauthenticated and unauthorized requests separately.