Web App Does Not Have Azure Active Directory Enabled
Overview
Managed service identity in App Service provides more security by eliminating secrets from the app, such as credentials in the connection strings. When registering with Azure Active Directory in App Service, the app will connect to other Azure services securely without the need for usernames and passwords.
App Service provides a highly scalable, self-patching web hosting service in Azure. It also provides a managed identity for apps, which is a turn-key solution for securing access to Azure SQL Database and other Azure services.
Vendor
Azure
Cloud Service
AppService
Related Controls
CIS Azure v2.0.0 9.5
References
https://docs.microsoft.com/en-gb/azure/app-service/app-service-web-tutorial-connect-msi, https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-identity-management#im-1-use-centralized-identity-and-authentication-system
Severity
4
Item Types
Microsoft.Web.sites