Azure App Service should have remote debugging disabled

Description

Azure App Services has ‘remote debugging’ disabled to enhance security and protect applications.

Rationale

If remote debugging is enabled, this can allow an attacker access to your applications. To reduce your attack surface, disable remote debugging when not actively needed.

Remediation

Azure CLI

  1. Get a list of your App Services web apps by running the following in Azure Powershell:

    az webapp list \
    --query '[*].id'
    
  2. Check the config of your web apps with the command:

    az webapp config show \
    --ids "<INSERT_ID_HERE>" \
    --query 'remoteDebuggingEnabled'
    
  3. Disable the web app’s remote debugging capability with the command:

    az webapp config set \
    --ids "<INSERT_ID_HERE>" \
    --remote-debugging-enabled false
    
  4. Repeat steps one through three for each server that is not configured correctly.

References

  1. Azure webapp config set