Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
windows_first
missing_linux_example
windows_tools
Summary
The documentation page demonstrates Windows bias in the 'Server level (Windows apps only)' section, where IIS and web.config-based authorization is described exclusively for Windows apps, with no Linux equivalent or alternative provided. Windows-specific tools (IIS, web.config) are mentioned, and Linux is only referenced to state that it is unsupported for these features, without offering guidance for Linux users.
Recommendations
  • Provide equivalent authorization guidance for Linux-based App Service apps, such as using middleware, configuration files (e.g., appsettings.json), or code samples for popular frameworks (Node.js, Python, .NET Core).
  • Include Linux-specific examples and tools where relevant, or link to external resources for Linux authorization patterns.
  • When describing platform-specific features, present both Windows and Linux options side-by-side, or clearly direct Linux users to alternative solutions.
  • Avoid language that simply states Linux is unsupported; instead, offer actionable alternatives or workarounds for Linux users.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-12 00:00 #99 completed Biased Biased
2026-01-11 06:20 #98 completed Biased Biased
2026-01-11 00:00 #95 cancelled Clean Clean
2026-01-10 00:00 #92 completed Biased Biased
2026-01-09 00:00 #87 cancelled Biased Biased
2026-01-08 00:00 #84 in_progress Clean Clean
2026-01-06 22:28 #78 completed Clean Clean
2025-12-29 18:00 #48 cancelled Biased Biased
2025-12-22 00:00 #24 cancelled Clean Clean
2025-12-15 00:00 #7 completed Clean Clean
2025-12-14 05:05 #6 completed Clean Clean

Flagged Code Snippets

5. Select **Put**.

This setting appends the `domain_hint` query string parameter to the sign-in redirect URL.

> [!IMPORTANT]
> It's possible for the client to remove the `domain_hint` parameter after receiving the redirect URL, and then sign in with a different domain. So although this function is convenient, it's not a security feature.

## Authorize or deny users

App Service takes care of the simplest authorization case, for example, reject unauthenticated requests. Your app might require more fine-grained authorization behavior, such as limiting access to only a specific group of users.

You might need to write custom application code to allow or deny access to the signed-in user. In some cases, App Service or your identity provider might be able to help without requiring code changes.

### Server level (Windows apps only)

For any Windows app, you can define authorization behavior of the IIS web server by editing the `web.config` file. Linux apps don't use IIS and can't be configured through `web.config`.

1. To go to the Kudu debug console for your app, select **Development Tools** > **Advanced Tools** and select **Go**. Then select **Debug console**.

   You can also open this page with this URL: `https://<app-name>-<random-hash>.scm.<region>.azurewebsites.net/DebugConsole`. To get the random hash and region values, in your app **Overview**, copy **Default domain**.

1. In the browser explorer of your App Service files, go to `site/wwwroot`. If `web.config` doesn't exist, create it by selecting **+** > **New File**.

1. Select the pencil for `web.config` to edit the file. Add the following configuration code, and then select **Save**. If `web.config` already exists, just add the `<authorization>` element with everything in it. In the `<allow>` element, add the accounts that you want to allow.