last sync: 2025-Oct-31 18:22:59 UTC

App Service apps should have local authentication methods disabled for SCM site deployments

Azure BuiltIn Policy definition

Source Azure Portal
Display name App Service apps should have local authentication methods disabled for SCM site deployments
Id aede300b-d67f-480a-ae26-4b3dfb1a1fdc
Version 1.0.3
Details on versioning
Versioning Versions supported for Versioning: 1
1.0.3
Built-in Versioning [Preview]
Category App Service
Microsoft Learn
Description Disabling local authentication methods for SCM sites improves security by ensuring that App Services exclusively require Microsoft Entra identities for authentication. Learn more at: https://aka.ms/app-service-disable-basic-auth.
Cloud environments AzureCloud = true
AzureUSGovernment = true
AzureChinaCloud = unknown
Available in AzUSGov The Policy is available in AzureUSGovernment cloud. Version: '1.0.3'
Repository: Azure-Policy aede300b-d67f-480a-ae26-4b3dfb1a1fdc
Mode Indexed
Type BuiltIn
Preview False
Deprecated False
Effect Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
RBAC role(s) none
Rule aliases THEN-ExistenceCondition (1)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Web/sites/basicPublishingCredentialsPolicies/allow Microsoft.Web sites/basicPublishingCredentialsPolicies properties.allow True True
Rule resource types IF (1)
Compliance
The following 1 compliance controls are associated with this Policy definition 'App Service apps should have local authentication methods disabled for SCM site deployments' (aede300b-d67f-480a-ae26-4b3dfb1a1fdc)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
Azure_Security_Benchmark_v3.0 IM-1 Azure_Security_Benchmark_v3.0_IM-1 Microsoft cloud security benchmark IM-1 Identity Management IM-1 Use centralized identity and authentication system Shared **Security Principle:** Use a centralized identity and authentication system to govern your organization's identities and authentications for cloud and non-cloud resources. **Azure Guidance:** Microsoft Entra ID is Azure's identity and authentication management service. You should standardize on Microsoft Entra ID to govern your organization's identity and authentication in: - Microsoft cloud resources, such as the Azure Storage, Azure Virtual Machines (Linux and Windows), Azure Key Vault, PaaS, and SaaS applications. - Your organization's resources, such as applications on Azure, third-party applications running on your corporate network resources, and third-party SaaS applications. - Your enterprise identities in Active Directory by synchronization to Microsoft Entra ID to ensure a consistent and centrally managed identity strategy. Note: As soon as it is technically feasible, you should migrate on-premises Active Directory based applications to Microsoft Entra ID. This could be a Microsoft Entra Enterprise Directory, Business to Business configuration, or Business to consumer configuration. **Implementation and additional context:** Tenancy in Microsoft Entra ID: https://docs.microsoft.com/azure/active-directory/develop/single-and-multi-tenant-apps How to create and configure a Microsoft Entra instance: https://docs.microsoft.com/azure/active-directory/fundamentals/active-directory-access-create-new-tenant Define Microsoft Entra ID tenants: https://azure.microsoft.com/resources/securing-azure-environments-with-azure-active-directory/ Use external identity providers for an application: https://docs.microsoft.com/azure/active-directory/b2b/identity-providers n/a link 22
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type polSet in AzUSGov
[Preview]: Microsoft cloud security benchmark v2 e3ec7e09-768c-4b64-882c-fcada3772047 Security Center Preview BuiltIn unknown
History
Date/Time (UTC ymd) (i) Change type Change detail
2023-09-22 17:59:46 change Patch (1.0.2 > 1.0.3)
2023-06-09 17:46:13 change Patch (1.0.1 > 1.0.2)
2022-07-01 16:32:34 change Patch (1.0.0 > 1.0.1)
2021-09-08 15:39:57 add aede300b-d67f-480a-ae26-4b3dfb1a1fdc
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC