last sync: 2025-Jul-03 17:22:55 UTC

[Deprecated]: Latest TLS version should be used in your API App

Azure BuiltIn Policy definition

Source Azure Portal
Display name [Deprecated]: Latest TLS version should be used in your API App
Id 8cb6aa8b-9e41-4f4e-aa25-089a7ac2581e
Version 1.0.0-deprecated
Details on versioning
Versioning Versions supported for Versioning: 1
1.0.0 (1.0.0-deprecated)
Built-in Versioning [Preview]
Category App Service
Microsoft Learn
Description Upgrade to the latest TLS version. We recommend all customers who are still using API Apps to implement the built-in policy called 'App Service apps should use the latest TLS version', which is scoped to include API apps in addition to Web Apps.
Cloud environments AzureCloud = true
AzureUSGovernment = unknown
AzureChinaCloud = unknown
Available in AzUSGov Unknown, no evidence if Policy definition is/not available in AzureUSGovernment
Assessment(s) Assessments count: 1
Assessment Id: 5a659d57-117d-bb18-65f6-54e51da1bb9b
DisplayName: TLS should be updated to the latest version for API apps
Description: The Transport Layer Security (TLS) protocol provides secure communication between web applications and servers.
Using outdated versions of TLS can expose the system to vulnerabilities and potential attacks.
By updating to the latest version, you can ensure the highest level of security for your API apps.

Remediation description: To update your API app to the latest TLS version:
1. Navigate to Azure App Service 2. Select TLS/SSL settings 3. Under the Protocol Settings section, choose the latest Minimum TLS Version.
For more information on managing TLS/SSL settings, visit here: https://aka.ms/add-tls
Categories: AppServices
Severity: High
preview: True
Mode Indexed
Type BuiltIn
Preview False
Deprecated True
Effect Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
RBAC role(s) none
Rule aliases THEN-ExistenceCondition (1)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Web/sites/config/minTlsVersion Microsoft.Web sites/config properties.minTlsVersion True False
Rule resource types IF (1)
Compliance
The following 7 compliance controls are associated with this Policy definition '[Deprecated]: Latest TLS version should be used in your API App' (8cb6aa8b-9e41-4f4e-aa25-089a7ac2581e)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
CIS_Azure_Foundations_v3.0.0 9.4 CIS_Azure_Foundations_v3.0.0_9.4 CIS Azure Foundations v3.0.0 9.4 9 Ensure Web App is Using the Latest Version of TLS Encryption Shared n/a Verify that the web application is configured to use the latest version of transport layer security (TLS) encryption. This control is crucial for ensuring secure communications by protecting data in transit from potential interception and vulnerabilities associated with outdated protocols. 3
K_ISMS_P_2018 2.10.1 K_ISMS_P_2018_2.10.1 K ISMS P 2018 2.10.1 2.10 Establish Procedures for Managing the Security of System Operations Shared n/a Establish and implement operating procedures for managing the security of system operations such as designating system administrators, updating policies, changing rulesets, monitoring events, managing policy implementations or exceptions. 455
K_ISMS_P_2018 2.10.2 K_ISMS_P_2018_2.10.2 K ISMS P 2018 2.10.2 2.10 Establish Protective Measures for Administrator Privileges and Security Configurations Shared n/a Establish and implement protective measures with regard to administrator privileges and security configurations to ensure that important information and personal information are not exposed as a result of unauthorized access by service type or misconfigurations. 431
K_ISMS_P_2018 2.10.4 K_ISMS_P_2018_2.10.4 K ISMS P 2018 2.10.4 2.10 Establish Protective Measures when Working with Electronic Transactions or Fintech Services Shared n/a Establish and implement protective measures such as authentication and encryption to prevent information leakage, data alteration, or fraud when working with electronic transactions and Fintech services. In the event connections to external systems are required, safety must be checked. 45
K_ISMS_P_2018 2.10.5 K_ISMS_P_2018_2.10.5 K ISMS P 2018 2.10.5 2.10 Establish Secure Data Transmission Procedures with External Organizations Shared n/a Establish secure transmission policies, transmission methods, and technical measures for protecting personal information and important information if transmitting data to external organizations. Agreement on management responsibilities for data transmission must be established. 30
K_ISMS_P_2018 2.10.8 K_ISMS_P_2018_2.10.8 K ISMS P 2018 2.10.8 2.10 Apply the Latest Patches to Software and Hardware Shared n/a Apply the latest patches to software and hardware to prevent vulnerabilities in operating systems and security systems. If the latest patch cannot be applied, supplemental protective measures must be implemented such as exception approval. 10
K_ISMS_P_2018 2.7.1b K_ISMS_P_2018_2.7.1b K ISMS P 2018 2.7.1b 2.7 Ensure Data is Encrypted at Rest and In-Transit Shared n/a Ensure data is encrypted when storing and transmitting personal and important information. 70
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type polSet in AzUSGov
CIS Azure Foundations v3.0.0 470a962c-86a0-433b-803a-3c176b5ce79c Regulatory Compliance GA BuiltIn unknown
K ISMS P 2018 e0782c37-30da-4a78-9f92-50bfe7aa2553 Regulatory Compliance GA BuiltIn unknown
History
Date/Time (UTC ymd) (i) Change type Change detail
2022-07-01 16:32:34 change Version remains equal, new suffix: deprecated (1.0.0 > 1.0.0-deprecated)
2019-10-29 23:04:36 add 8cb6aa8b-9e41-4f4e-aa25-089a7ac2581e
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC