Skip to content

Ensure 'HTTPS Only' is set to On

Why This Matters

HTTP traffic transmits data in plain text, making it vulnerable to interception, eavesdropping, and man-in-the-middle attacks. Enforcing HTTPS ensures all data exchanged between users and your web app is encrypted and authenticated via TLS/SSL, protecting sensitive information like credentials and personal data from exposure.

What Aether365 Checks

This security check verifies that the "HTTPS Only" setting is set to On for each Azure App Service. You will find this check in the Aether365 dashboard under the azure-app-services category.

Microsoft references

Was this page helpful?