Review Azure Web App HTTPS enforcement

Use HTTPS for web requests and never send sensitive information over plaintext HTTP.

Description

Login data, session cookies, and user input sent over HTTP can be observed or altered. App Service’s https_only = true redirects HTTP requests to HTTPS. It does not encrypt the initial HTTP request, so clients should use HTTPS from the start.

Potential impact

Plaintext HTTP can expose data in transit and permit request tampering or session theft.

Remediation

Set https_only = true and configure app links, API clients, and redirects to use HTTPS. Check certificates, minimum TLS versions, secure cookies, and a suitable HSTS policy. Test that sensitive data is not sent over HTTP first.

Examples

These are legacy AzureRM 3.x azurerm_app_service examples. Current Linux and Windows Web App resources also support https_only.

Before

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
  }

  https_only = false
}

After

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
  }

  https_only = true
}

The revision redirects HTTP requests to HTTPS. It does not replace user authentication or authorization.

References