Create Pull Request
| Date | Scan | Status | Result |
|---|---|---|---|
| 2026-01-12 00:00 | #99 | completed |
Biased
|
| 2026-01-11 06:20 | #98 | completed |
Biased
|
| 2026-01-11 00:00 | #95 | cancelled |
Clean
|
| 2026-01-10 00:00 | #92 | completed |
Biased
|
| 2026-01-09 00:00 | #87 | cancelled |
Biased
|
| 2026-01-08 00:00 | #84 | in_progress |
Clean
|
| 2026-01-06 22:28 | #78 | completed |
Clean
|
| 2025-12-29 18:00 | #48 | cancelled |
Biased
|
| 2025-12-22 00:00 | #24 | cancelled |
Clean
|
| 2025-12-15 00:00 | #7 | completed |
Clean
|
| 2025-12-14 05:05 | #6 | completed |
Clean
|
5. Select **Put**.
This setting appends the `domain_hint` query string parameter to the sign-in redirect URL.
> [!IMPORTANT]
> It's possible for the client to remove the `domain_hint` parameter after receiving the redirect URL, and then sign in with a different domain. So although this function is convenient, it's not a security feature.
## Authorize or deny users
App Service takes care of the simplest authorization case, for example, reject unauthenticated requests. Your app might require more fine-grained authorization behavior, such as limiting access to only a specific group of users.
You might need to write custom application code to allow or deny access to the signed-in user. In some cases, App Service or your identity provider might be able to help without requiring code changes.
### Server level (Windows apps only)
For any Windows app, you can define authorization behavior of the IIS web server by editing the `web.config` file. Linux apps don't use IIS and can't be configured through `web.config`.
1. To go to the Kudu debug console for your app, select **Development Tools** > **Advanced Tools** and select **Go**. Then select **Debug console**.
You can also open this page with this URL: `https://<app-name>-<random-hash>.scm.<region>.azurewebsites.net/DebugConsole`. To get the random hash and region values, in your app **Overview**, copy **Default domain**.
1. In the browser explorer of your App Service files, go to `site/wwwroot`. If `web.config` doesn't exist, create it by selecting **+** > **New File**.
1. Select the pencil for `web.config` to edit the file. Add the following configuration code, and then select **Save**. If `web.config` already exists, just add the `<authorization>` element with everything in it. In the `<allow>` element, add the accounts that you want to allow.