App Service and Function apps that still answer plain HTTP requests
What does ZopNight detect here?
ZopNight flags a web app or function app whose `httpsOnly` property is false. HTTPS Only is not on by default in App Service, so such an app still accepts plain HTTP, and anything a client sends that way travels unencrypted. The fix is one `az webapp update --https-only true` call, and no cost or saving is involved.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1311 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | httpsOnly = false |
| Source | ZopNight |
| Permissions used | Microsoft.Web/sites/Read |
Where it applies
HTTPS Only is an opt-in switch
App Service serves every app on both HTTP and HTTPS. The HTTPS Only setting, stored as the
site’s httpsOnly property, redirects plain HTTP requests to HTTPS.
Microsoft’s App Service security guidance
says this redirect is not on by default and must be enabled explicitly.
Until it is, a bookmark, an old link or a misconfigured client can send session cookies, tokens and form posts in clear text, where anyone on the path can read or change them.
Listing apps that still accept HTTP
az webapp list \ --query "[?httpsOnly==\`false\`].{name:name, rg:resourceGroup}" -o tableaz functionapp list \ --query "[?httpsOnly==\`false\`].{name:name, rg:resourceGroup}" -o tableWhile you are there, check the minimum TLS version with
az webapp config show --resource-group my-rg --name my-app --query minTlsVersion.
A single property decides the finding
ZopNight reads the app’s own httpsOnly value as Azure reports it and fires only when that
value is false. The check applies to web apps and function apps, since both are sites; the App
Service plan they run on is not evaluated, because HTTPS Only is set per app. There is no
metric or window.
Apps that are not flagged
An app whose HTTPS Only value was not returned is treated as unknown and skipped. Tags on the
app are ignored. Note one quirk: an app with built-in authentication on already redirects HTTP
to HTTPS, but ZopNight still flags it when httpsOnly is false, because turning authentication
off later would silently reopen HTTP.
Interception risk rather than cost
There is no saving attached. The exposure is data in transit, including credentials, readable or modifiable by anyone between the client and the app.
Forcing HTTPS on the app
- Turn on HTTPS Only:
az webapp update --resource-group my-rg --name my-app --https-only true(for function apps,az functionapp update --resource-group my-rg --name my-func --set httpsOnly=true). - Set the minimum TLS version to 1.2 or higher:
az webapp config set --resource-group my-rg --name my-app --min-tls-version 1.2. App Service supports TLS 1.3 and uses 1.2 as its default minimum. - Make sure each custom domain has a TLS certificate bound, or HTTPS visitors will see a certificate error after the redirect.
- Update any client or webhook sender that still posts to an
http://URL; a redirect does not help clients that refuse to follow it.