Skip to content

Expose frontend HTTP endpoints over HTTPS#

Security ยท Application Gateway ยท Azure.AppGw.UseHTTPS

Application Gateways should only expose frontend HTTP endpoints over HTTPS.

Description#

Application Gateways support HTTP and HTTPS endpoints for backend and frontend traffic. When using frontend HTTP (80) endpoints, traffic between client and Application Gateway is not encrypted.

Unencrypted communication could allow disclosure of information to an un-trusted party.

Recommendation#

Consider configuring Application Gateways to only expose HTTPS endpoints. For client applications such as progressive web apps, consider redirecting HTTP traffic to HTTPS.


Last update: 2021-09-24