last sync: 2024-Nov-25 18:54:24 UTC

App Service app slots should have Client Certificates (Incoming client certificates) enabled

Azure BuiltIn Policy definition

Source Azure Portal
Display name App Service app slots should have Client Certificates (Incoming client certificates) enabled
Id 5b0bd968-5cb5-4513-8987-27786c6f0df8
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 1
1.0.0
Built-in Versioning [Preview]
Category App Service
Microsoft Learn
Description Client certificates allow for the app to request a certificate for incoming requests. Only clients that have a valid certificate will be able to reach the app. This policy applies to apps with Http version set to 1.1.
Mode Indexed
Type BuiltIn
Preview False
Deprecated False
Effect Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
RBAC role(s) none
Rule aliases IF (1)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Web/sites/slots/clientCertEnabled Microsoft.Web sites/slots properties.clientCertEnabled True False
THEN-ExistenceCondition (1)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Web/sites/slots/config/web.http20Enabled Microsoft.Web sites/slots/config properties.http20Enabled True False
Rule resource types IF (1)
Microsoft.Web/sites/slots
Compliance
The following 1 compliance controls are associated with this Policy definition 'App Service app slots should have Client Certificates (Incoming client certificates) enabled' (5b0bd968-5cb5-4513-8987-27786c6f0df8)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
New_Zealand_ISM 14.5.8.C.01 New_Zealand_ISM_14.5.8.C.01 New_Zealand_ISM_14.5.8.C.01 14. Software security 14.5.8.C.01 Web applications n/a Agencies SHOULD follow the documentation provided in the Open Web Application Security Project guide to building secure Web applications and Web services. 18
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type
New Zealand ISM 4f5b1359-4f8e-4d7c-9733-ea47fcde891e Regulatory Compliance GA BuiltIn
History
Date/Time (UTC ymd) (i) Change type Change detail
2023-12-08 20:47:07 add 5b0bd968-5cb5-4513-8987-27786c6f0df8
JSON compare n/a
JSON
api-version=2021-06-01
EPAC