last sync: 2025-Jul-11 17:24:21 UTC

[Deprecated]: API App should only be accessible over HTTPS

Azure BuiltIn Policy definition

Source Azure Portal
Display name [Deprecated]: API App should only be accessible over HTTPS
Id b7ddfbdc-1260-477d-91fd-98bd9be789a6
Version 1.0.0-deprecated
Details on versioning
Versioning Versions supported for Versioning: 1
1.0.0 (1.0.0-deprecated)
Built-in Versioning [Preview]
Category App Service
Microsoft Learn
Description Use of HTTPS ensures server/service authentication and protects data in transit from network layer eavesdropping attacks. We recommend all customers who are still using API Apps to implement the built-in policy called 'App Service apps should only be accessible over HTTPS', which is scoped to include API apps in addition to Web Apps.
Cloud environments AzureCloud = true
AzureUSGovernment = unknown
AzureChinaCloud = unknown
Available in AzUSGov Unknown, no evidence if Policy definition is/not available in AzureUSGovernment
Assessment(s) Assessments count: 1
Assessment Id: bf82a334-13b6-ca57-ea75-096fc2ffce50
DisplayName: API App should only be accessible over HTTPS
Description: Use of HTTPS ensures server/service authentication and protects data in transit from network layer eavesdropping attacks.
Remediation description: To redirect all HTTP traffic to HTTPS, we recommend the following steps:
1. Go to the API App custom domains page
2. In the HTTPS Only toggle select On
Categories: AppServices
Severity: Medium
User impact: Moderate
Implementation effort: Low
Threats: DataExfiltration, DataSpillage, MaliciousInsider
Mode Indexed
Type BuiltIn
Preview False
Deprecated True
Effect Default
Audit
Allowed
Audit, Disabled
RBAC role(s) none
Rule aliases IF (1)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Web/sites/httpsOnly Microsoft.Web sites properties.httpsOnly True True
Rule resource types IF (1)
Compliance
The following 4 compliance controls are associated with this Policy definition '[Deprecated]: API App should only be accessible over HTTPS' (b7ddfbdc-1260-477d-91fd-98bd9be789a6)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
CIS_Azure_Foundations_v3.0.0 9.1 CIS_Azure_Foundations_v3.0.0_9.1 CIS Azure Foundations v3.0.0 9.1 9 Ensure 'HTTPS Only' is set to 'On' Shared n/a Verify that the 'HTTPS Only' setting is configured to 'On' for all applicable Azure resources. This control is essential for ensuring that all communications are secured using HTTPS, protecting data in transit from interception and unauthorized access. 3
K_ISMS_P_2018 2.10.1 K_ISMS_P_2018_2.10.1 K ISMS P 2018 2.10.1 2.10 Establish Procedures for Managing the Security of System Operations Shared n/a Establish and implement operating procedures for managing the security of system operations such as designating system administrators, updating policies, changing rulesets, monitoring events, managing policy implementations or exceptions. 408
K_ISMS_P_2018 2.10.2 K_ISMS_P_2018_2.10.2 K ISMS P 2018 2.10.2 2.10 Establish Protective Measures for Administrator Privileges and Security Configurations Shared n/a Establish and implement protective measures with regard to administrator privileges and security configurations to ensure that important information and personal information are not exposed as a result of unauthorized access by service type or misconfigurations. 385
K_ISMS_P_2018 2.10.5 K_ISMS_P_2018_2.10.5 K ISMS P 2018 2.10.5 2.10 Establish Secure Data Transmission Procedures with External Organizations Shared n/a Establish secure transmission policies, transmission methods, and technical measures for protecting personal information and important information if transmitting data to external organizations. Agreement on management responsibilities for data transmission must be established. 28
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type polSet in AzUSGov
CIS Azure Foundations v3.0.0 470a962c-86a0-433b-803a-3c176b5ce79c Regulatory Compliance GA BuiltIn unknown
K ISMS P 2018 e0782c37-30da-4a78-9f92-50bfe7aa2553 Regulatory Compliance GA BuiltIn unknown
History
Date/Time (UTC ymd) (i) Change type Change detail
2022-06-07 16:30:19 change Version remains equal, new suffix: deprecated (1.0.0 > 1.0.0-deprecated)
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC