Skip to main content
compliance · azure

App Service and Function apps that still answer plain HTTP requests

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags a web app or function app whose `httpsOnly` property is false. HTTPS Only is not on by default in App Service, so such an app still accepts plain HTTP, and anything a client sends that way travels unencrypted. The fix is one `az webapp update --https-only true` call, and no cost or saving is involved.

Signal and threshold

How ZopNight evaluates App Service and Function apps that still answer plain HTTP requests.
Field Value
Rule IDsRC-1311
Categorycompliance
Severityhigh
Metricnone — pure configuration read
ThresholdhttpsOnly = false
SourceZopNight
Permissions usedMicrosoft.Web/sites/Read

HTTPS Only is an opt-in switch

App Service serves every app on both HTTP and HTTPS. The HTTPS Only setting, stored as the site’s httpsOnly property, redirects plain HTTP requests to HTTPS. Microsoft’s App Service security guidance says this redirect is not on by default and must be enabled explicitly.

Until it is, a bookmark, an old link or a misconfigured client can send session cookies, tokens and form posts in clear text, where anyone on the path can read or change them.

Listing apps that still accept HTTP

Terminal window
az webapp list \
--query "[?httpsOnly==\`false\`].{name:name, rg:resourceGroup}" -o table
az functionapp list \
--query "[?httpsOnly==\`false\`].{name:name, rg:resourceGroup}" -o table

While you are there, check the minimum TLS version with az webapp config show --resource-group my-rg --name my-app --query minTlsVersion.

A single property decides the finding

ZopNight reads the app’s own httpsOnly value as Azure reports it and fires only when that value is false. The check applies to web apps and function apps, since both are sites; the App Service plan they run on is not evaluated, because HTTPS Only is set per app. There is no metric or window.

Apps that are not flagged

An app whose HTTPS Only value was not returned is treated as unknown and skipped. Tags on the app are ignored. Note one quirk: an app with built-in authentication on already redirects HTTP to HTTPS, but ZopNight still flags it when httpsOnly is false, because turning authentication off later would silently reopen HTTP.

Interception risk rather than cost

There is no saving attached. The exposure is data in transit, including credentials, readable or modifiable by anyone between the client and the app.

Forcing HTTPS on the app

  1. Turn on HTTPS Only: az webapp update --resource-group my-rg --name my-app --https-only true (for function apps, az functionapp update --resource-group my-rg --name my-func --set httpsOnly=true).
  2. Set the minimum TLS version to 1.2 or higher: az webapp config set --resource-group my-rg --name my-app --min-tls-version 1.2. App Service supports TLS 1.3 and uses 1.2 as its default minimum.
  3. Make sure each custom domain has a TLS certificate bound, or HTTPS visitors will see a certificate error after the redirect.
  4. Update any client or webhook sender that still posts to an http:// URL; a redirect does not help clients that refuse to follow it.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·