Review App Service FTP transport protection

Use FTPS for file transfer and disable FTP access when it is unnecessary.

Description

site_config.ftps_state = "AllAllowed" permits unencrypted FTP as well. Using plaintext FTP can expose credentials and file contents in transit. Restrict required file transfers to FTPS, or disable the FTP feature when it is unused.

Potential impact

An attacker able to observe or alter plaintext traffic may target publishing credentials and deployment files.

Remediation

Set site_config.ftps_state to FtpsOnly, or Disabled when FTP is unnecessary. Verify that clients use TLS and validate the server certificate, and restrict and manage publishing credentials. Check authentication and transport protection on any alternative deployment path.

Examples

These examples use the legacy AzureRM 3.x azurerm_app_service resource. Current Linux and Windows Web App resources also expose the FTP state setting.

Before

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
    ftps_state               = "AllAllowed"
  }
}

After

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
    ftps_state               = "FtpsOnly"
  }
}

The revision permits FTPS only. This protects the file-transfer channel; it does not replace HTTPS-only settings or user authentication for the web app.

References