App Service web app authentication should be enabled

Description

Azure App Service Authentication is a feature that can prevent anonymous HTTP requests from reaching the API app, or authenticate those that have tokens before they reach the API app. If an anonymous request is received from a browser, App Service will redirect to a logon page. To handle the logon process, a choice from a set of identity providers can be made, or a custom authentication mechanism can be implemented.

Portal Remediation Steps

  • Navigate to App Services.

  • In the left navigation, select Authentication/Authorization.

  • In App Service Authentication, select On and click Save.

CLI Remediation Steps

  • To enable web app authentication, follow the Azure documentation for az webapp auth update and set --enabled true:

az webapp auth update --resource-group <RESOURCE_GROUP_NAME> --name <APP_NAME> --enabled true