Proposed Pull Request Change

title description author ms.author ms.service ms.topic ms.custom ms.date ai-usage
Secure your Azure Container Apps deployment Learn how to secure Azure Container Apps, with best practices for protecting your deployment. msmbaldwin mbaldwin azure-container-apps best-practice horz-security 09/04/2026 ai-assisted
📄 Document Links
GitHub View on GitHub Microsoft Learn View on Microsoft Learn
⚠ Content Truncation Detected
The generated rewrite appears to be incomplete.
Original lines: -
Output lines: -
Ratio: -
Raw New Markdown
Generating updated version of doc...
Rendered New Markdown
Generating updated version of doc...
+0 -0
+0 -0
--- title: Secure your Azure Container Apps deployment description: Learn how to secure Azure Container Apps, with best practices for protecting your deployment. author: msmbaldwin ms.author: mbaldwin ms.service: azure-container-apps ms.topic: best-practice ms.custom: horz-security ms.date: 09/04/2026 ai-usage: ai-assisted --- # Secure your Azure Container Apps deployment Azure Container Apps provides capabilities to run containerized applications without managing complex infrastructure while providing enterprise-grade security features. When deploying this service, follow security best practices to protect data, configurations, and infrastructure. This article provides security recommendations to help protect your Azure Container Apps deployment. [!INCLUDE [Security horizontal Zero Trust statement](~/reusable-content/ce-skilling/azure/includes/security/zero-trust-security-horizontal.md)] ## Service-specific security Container Apps provides unique security capabilities designed specifically for containerized workloads, microservices architectures, and cloud-native applications. - **Configure environment-level security boundaries**: Use Container Apps environments to create security boundaries between different applications and workloads. Separate production and nonproduction environments to prevent unauthorized access and configuration drift. For more information, see [Environment overview](/azure/container-apps/environment). - **Implement proper scaling and resource limits**: Configure appropriate scaling rules and resource limits to prevent resource exhaustion attacks and ensure fair resource allocation among applications. Monitor scaling events for unusual patterns that might indicate security issues. For more information, see [Set scaling rules in Azure Container Apps](/azure/container-apps/scale-app). ## Network security Network security controls prevent unauthorized access to container app endpoints and establish secure communication boundaries between your applications and external services. - **Deploy container apps in a virtual network**: To control network traffic and secure access to backend resources, integrate your container app environment with Azure Virtual Networks. Virtual network integration enables your apps to access resources in private networks while protecting against internet-based attacks. For more information, see [Virtual network configuration](/azure/container-apps/custom-virtual-networks). - **Enable private endpoints for inbound access**: Eliminate public internet exposure by using Azure Private Link to route client traffic through your virtual network. Private endpoints provide a private IP address from your virtual network, effectively bringing your container app into your network perimeter. For more information, see [Use a private endpoint with an Azure Container Apps environment](/azure/container-apps/how-to-use-private-endpoint). - **Configure internal environments for complete isolation**: Deploy internal Container Apps environments to restrict all inbound access to clients within your virtual network. Internal environments provide complete isolation from the public internet and enable secure communication between container apps and other network resources. For more information, see [Networking in Azure Container Apps environment](/azure/container-apps/networking). - **Disable public network access**: Configure Container Apps environments to disable public network access when using private endpoints, ensuring all connectivity occurs through your controlled virtual network environment. This configuration prevents unauthorized external access attempts. For more information, see [Private endpoints and DNS for virtual networks in Azure Container Apps environments](/azure/container-apps/private-endpoints-with-dns). - **Implement Azure Firewall for outbound traffic control**: Use Azure Firewall with user-defined routes (UDR) to control and monitor all outbound traffic from your container apps to ensure communication only occurs with approved destinations. For more information, see [Enable User Defined Routes (UDR)](/azure/container-apps/user-defined-routes). - **Configure network security groups with restrictive rules**: Apply network security groups to control traffic flow to and from your Container Apps subnets by implementing deny-by-default policies with specific allow rules for required communication patterns. For more information, see [Secure an existing virtual network with a network security group](/azure/container-apps/firewall-integration). - **Configure app-level restrictions**: Configure ingress settings with appropriate security controls including client certificate authentication and IP restrictions for secure exposure of container applications. Use internal ingress for applications that shouldn't be accessible from the internet. For more information, see [Ingress overview](/azure/container-apps/ingress-overview). ## Identity and access management Identity and access management controls ensure that only authorized users and applications can access Container Apps resources with appropriate permissions and authentication mechanisms. - **Enable authentication and authorization**: Configure built-in authentication using Microsoft Entra ID and other identity providers to protect container app endpoints beyond basic access controls. This configuration provides centralized identity management and supports custom authorization rules. For more information, see [Authentication and authorization in Azure Container Apps](/azure/container-apps/authentication). - **Use managed identities for service connections**: Configure system-assigned or user-assigned managed identities to authenticate to other Azure services without storing credentials in code or configuration. Managed identities eliminate credential management overhead and provide automatic secret rotation. For more information, see [Use managed identities in Azure Container Apps](/azure/container-apps/managed-identity). - **Implement role-based access control (RBAC)**: Assign only the permissions required for each Container Apps management task. Container Apps-specific built-in roles can provide narrower access than broad Contributor or Owner assignments, but some use wildcard permissions that include actions for reading secret values. If no built-in role provides the access boundary you need, create a custom role with explicit permissions. For more information, see [Permissions for managing secrets](manage-secrets.md#permissions-for-managing-secrets) and [Azure built-in roles for containers](/azure/role-based-access-control/built-in-roles/containers). - **Configure Microsoft Entra ID authentication**: Use Microsoft Entra ID for centralized identity management and enable conditional access policies to control access based on user, location, and device conditions. This configuration provides enterprise-grade authentication capabilities with multifactor authentication support. For more information, see [Enable authentication and authorization in Azure Container Apps with Microsoft Entra ID](/azure/container-apps/authentication-entra). - **Enable token store for secure authentication**: Use the built-in token store feature to manage authentication tokens securely independent of your application code. The token store provides automatic token refresh and reduces attack surface by eliminating custom token management code. For more information, see [Enable an authentication token store](/azure/container-apps/token-store). ## Data protection Data protection mechanisms safeguard sensitive information processed by container apps through encryption, secure storage, and proper handling of secrets and configuration data. - **Enforce HTTPS for all communication**: Configure Envoy proxy to redirect all HTTP traffic to HTTPS to ensure all data transmission uses TLS encryption. Set `allowInsecure: false` in your ingress configuration to prevent unencrypted connections. For more information, see [Set up HTTPS or TCP ingress in Azure Container Apps](/azure/container-apps/ingress). - **Use Azure Key Vault for secrets management**: Store connection strings, API keys, and other secrets in Azure Key Vault instead of application settings. Use Key Vault references to retrieve secrets at runtime while maintaining centralized secret management with enhanced security and audit capabilities. For more information, see [Manage secrets in Azure Container Apps](/azure/container-apps/manage-secrets). - **Enable mutual Transport Layer Security (mTLS)**: Use mTLS to authenticate and encrypt traffic between services, providing bidirectional authentication that verifies both client and server identities. This feature enhances security for service-to-service communication within your container app environment. For more information, see [Use Mutual Transport Layer Security (mTLS)](/azure/container-apps/mtls). - **Implement proper secrets management**: Use the Container Apps built-in secrets store to hold sensitive values with proper isolation and access controls, and avoid storing secrets directly in container images or environment variables. For more information, see [Permissions for managing secrets](manage-secrets.md#permissions-for-managing-secrets). - **Secure container image storage**: Store container images in Azure Container Registry with authentication enabled and configure geo-replication for disaster recovery. Use private registries instead of public repositories for production workloads to maintain control over image access. For more information, see [Authenticate with an Azure container registry](/azure/container-registry/container-registry-authentication). ## Logging and monitoring Comprehensive logging and monitoring provide visibility into Container Apps operations, security events, and performance metrics to enable threat detection and operational oversight. - **Enable Azure Monitor Log Analytics integration**: Configure Log Analytics workspace integration to collect and analyze system and application logs from all container apps in your environment. This configuration provides centralized log management and supports security monitoring and compliance auditing. For more information, see [Monitor logs in Azure Container Apps with Log Analytics](/azure/container-apps/log-monitoring). - **Configure diagnostic settings**: Enable diagnostic settings to stream container app logs and metrics to Azure Monitor Logs, storage accounts, or Event Hubs for centralized analysis and long-term retention. This configuration supports security investigations and compliance requirements. For more information, see [Observability in Azure Container Apps](/azure/container-apps/observability). - **Set up Azure Monitor alerts**: Configure alerts for suspicious activities including failed authentications, unusual traffic patterns, high error rates, and resource consumption anomalies. Use action groups to enable automated response to potential security incidents. For more information, see [Azure Monitor alerts](/azure/container-apps/alerts). - **Enable log streaming for real-time monitoring**: Use log streaming capabilities to view near real-time system and console logs from containers for immediate troubleshooting and security event detection. This capability enables rapid response during security incidents. For more information, see [Log streaming](/azure/container-apps/log-streaming). - **Implement Application Insights integration**: Configure Application Insights integration to capture detailed telemetry, performance metrics, and custom traces from your container applications. This integration provides comprehensive observability for security analysis and performance optimization. For more information, see [Application Insights overview](/azure/azure-monitor/app/app-insights-overview). ## Compliance and governance Compliance and governance controls ensure Container Apps deployments meet regulatory requirements and organizational policies through proper configuration management and audit capabilities. - **Apply Azure Policy definitions**: Use built-in Azure Policy definitions to audit and enforce security configurations such as virtual network deployment, authentication requirements, and HTTPS enforcement. Policies help maintain consistent security posture across environments. For more information, see [Azure Policy built-in definitions for Azure Container Apps](/azure/container-apps/policy-reference). - **Implement resource tagging**: Apply consistent resource tags to Container Apps resources for cost management, security monitoring, compliance tracking, and governance. Use tags to identify data classification, owner information, and regulatory requirements. For more information, see [Use tags to organize your Azure resources](/azure/azure-resource-manager/management/tag-resources). - **Configure conditional access policies**: Apply Microsoft Entra Conditional Access policies that require multifactor authentication and compliant devices for identities that manage Container Apps and its environments, and for end-user access protected by the built-in authentication feature. For more information, see [Require MFA for Azure management](/entra/identity/conditional-access/policy-old-require-mfa-azure-mgmt). - **Maintain audit trails and compliance documentation**: Ensure comprehensive logging captures all container app administrative actions, configuration changes, and access attempts for regulatory compliance and security investigations by using diagnostic settings and activity logs. For more information, see [Azure Activity log](/azure/azure-monitor/essentials/activity-log). ## Backup and recovery Backup and recovery strategies protect container app configurations and ensure business continuity through proper disaster recovery planning and multiregion deployment strategies. - **Enable zone redundancy for high availability**: Configure zone redundancy in Container Apps environments to automatically distribute replicas across multiple availability zones within a region. This configuration protects against zone-level failures and improves application uptime. For more information, see [Reliability in Azure Container Apps](/azure/reliability/reliability-azure-container-apps). - **Implement multiregion deployments**: Deploy Container Apps across multiple Azure regions by using Azure Front Door or Azure Traffic Manager for automatic failover capabilities during regional outages. This strategy ensures continuous application availability for critical workloads. For more information, see [Resilience to region-wide failures](/azure/reliability/reliability-azure-container-apps#resilience-to-region-wide-failures). - **Use infrastructure as code for deployment automation**: Implement automated deployment processes by using Azure Resource Manager templates, Bicep, or other infrastructure as code tools to ensure you can quickly redeploy container app configurations after incidents or in alternate regions. For more information, see [Azure Resource Manager and Bicep API specification for Azure Container Apps](/azure/container-apps/azure-resource-manager-api-spec). - **Configure geo-redundant container registry**: Use Azure Container Registry with geo-replication enabled to ensure container images are available across multiple regions for disaster recovery scenarios. This configuration protects against registry outages and supports multiregion deployments. For more information, see [Geo-replication in Azure Container Registry](/azure/container-registry/container-registry-geo-replication). - **Test disaster recovery procedures**: Regularly test backup and recovery procedures including application deployment, configuration restoration, and failover processes to validate effectiveness and identify gaps in disaster recovery planning. Document test results and update procedures based on lessons learned. For more information, see [Custom multiregion solutions for resiliency](/azure/reliability/reliability-azure-container-apps#custom-multiregion-solutions-for-resiliency). ## Next steps - [Well-Architected Framework – Azure Container Apps guide](/azure/well-architected/service-guides/azure-container-apps) - [Zero Trust guidance center](/security/zero-trust/zero-trust-overview) - [Microsoft Cloud Security Benchmark v2 (preview)](/security/benchmark/azure/overview) - [Azure Security Documentation](/azure/security/)
Success! Branch created successfully. Create Pull Request on GitHub
Error: