MicrosoftDocs/azure-docs/articles/app-service

Last 20 commits touching this section.

7fc1e09

Merge pull request #321219 from seligj95/seligj95-windows-outbound-ip-overlap Document Windows App Service worker IP overlap limitation

19f0e4d

Document Windows App Service worker IP overlap limitation Explain local-address conflicts for outbound VNet connections and add SKU-specific infrastructure CIDRs for subnet planning. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

14a593a

Update app-service-app-service-environment-custom-settings.md

ef12a53

Revise date and vCore details in overview.md Updated the date and clarified vCore allocation for dedicated hosts.

7b25f59

Document managed connectors for App Service with language pivots (#320836) * Document managed connectors for App Service with language pivots Add callback, authentication, and SDK action guidance for C#, JavaScript, TypeScript, and Python, plus connectivity and Functions cross-links. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Link managed connector samples in each App Service language pivot Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Document single-language sample deployment and address review feedback Clarify selected-language provisioning, deployment outputs, authentication, and cleanup; apply the seven authoring suggestions. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Render connectivity comparison bullets as HTML lists Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Update managed connectors article author metadata Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Refocus managed connectors overview on App Service concepts Remove sample deployment mechanics and describe authentication and connection access independently of the sample repositories. Retain inline examples and supporting sample links. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Use public App Service authentication terminology Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Link App Service guidance from Connector Namespace docs Address Lily's discovery feedback in the supported compute list and namespace creation guide. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

c2e1b06

Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/azure-docs (branch main) (#320862) * Fix the stale Application Insights cross-reference in the isolated worker migration guide (#128800) * App Service Certificate: what a renew or rekey does before the paid term ends (#128793) * App Service Certificate: explain why a rekey keeps the existing expiration date * App Service Certificate: explain what a renew does before the paid term ends * Say the manual renew window is the 90 days before expiry * Use rekey instead of reissue for consistency * Address review: 200-day max, full-year charge wording, rekey example, drop buy-new and rekey-after-renew * Use the 198-day ASC maximum --------- Co-authored-by: Elle Tojaroon <elletojaroon@microsoft.com> --------- Co-authored-by: learn-build-service-prod[bot] <113403604+learn-build-service-prod[bot]@users.noreply.github.com> Co-authored-by: Fabian <fabian@fzankl.de> Co-authored-by: Elle Tojaroon <15943485+ElleTojaroon@users.noreply.github.com> Co-authored-by: Elle Tojaroon <elletojaroon@microsoft.com>

896b722

Merge pull request #320765 from Hectoruu/US-629654-broken-links-dat-53 2026_09 - Fix monthly broken links

e2522b1

Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/azure-docs (branch main) (#320794) * doc: update add bindings existing function doc (#128803) * Fix wording in add-bindings-existing-function doc Signed-off-by: Rawal27 <obviouslykamal@gmail.com> * Fix wording in add-bindings-existing-function doc Signed-off-by: Rawal27 <obviouslykamal@gmail.com> --------- Signed-off-by: Rawal27 <obviouslykamal@gmail.com> * Update App Service representation in documentation (#128802) Clarified the representation of App Service in RBAC and access policies, specifying 'Microsoft Azure App Service' in the documentation. --------- Signed-off-by: Rawal27 <obviouslykamal@gmail.com> Co-authored-by: learn-build-service-prod[bot] <113403604+learn-build-service-prod[bot]@users.noreply.github.com> Co-authored-by: Saisang Cai <Saisang@users.noreply.github.com> Co-authored-by: Kamal Rawal <obviouslykamal@gmail.com> Co-authored-by: Learn Build Service GitHub App <Learn Build Service LearnBuild@microsoft.com> Co-authored-by: Amy Luu <38671376+amyluums@users.noreply.github.com>

0775cc4

Revise email confirmation note in tutorial Updated the note to use italics for 'Create action' and clarified the guidance on using HttpClient.

2919362

Update configure-authentication-provider-openid-connect.md

30f765e

Remove token generation reference from Apple auth doc Removed redundant information about generating and validating tokens.

3a3ed64

Merge pull request #320644 from apwestgarth/apw_java81117 Updated doc with steps to report

7356c72

Update articles/app-service/configure-language-java-deploy-run.md Co-authored-by: learn-build-service-prod-04[bot] <274428985+learn-build-service-prod-04[bot]@users.noreply.github.com>

9e6ea32

Updated text.

cf0dbed

Simplifying example to search for apps using Java 8, 11 and 17

731b1d2

Merge pull request #320668 from seligj95/seligj95-app-service-endpoint-ipv4 Document App Service private endpoint IP mode requirements

a1c6e4f

docs: clarify App Service private endpoint IP mode requirements Document the IPv4 requirement for private endpoint connectivity and warn against IPv6-only mode in the IPv6 configuration guidance. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

0e0b12b

Updated doc with steps to report apps using Java 8, 11 and 17

e51d1a1

Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/azure-docs (branch main) (#320467) * Note that Newtonsoft serialization attributes stop working after migration (#128734) Follow-up to the `AllowSynchronousIO` clarification in #128726 and the *Migrate to asynchronous HTTP stream I/O* section that was added alongside it. That async guidance is correct as written: replacing `ReadToEnd` with `ReadToEndAsync` keeps the same serializer, so a migrated app keeps behaving identically. This PR covers a step of the migration that isn't behavior-preserving. ## Problem The in-process model used *Newtonsoft.Json*. The isolated worker model uses *System.Text.Json* by default. Types that a migrated app binds to usually still carry *Newtonsoft.Json* attributes (`[JsonProperty("customer_name")]` being the common one), and *System.Text.Json* doesn't recognize them. It binds the affected property to its default value and reports nothing: HTTP 200, property `null`, no exception and no log entry. The *JSON serialization* section of this guide covers the serializer switch itself and links to *Customizing JSON serialization* for options and for moving back to JSON.NET. It says nothing about the attributes already sitting on the reader's types. `JsonProperty` and `JsonPropertyName` currently appear nowhere in this guide, its includes, or `dotnet-isolated-process-guide.md`, so a reader whose property silently stops binding has nothing to search for. Measured on `Microsoft.Azure.Functions.Worker` 2.52.0, `Microsoft.Azure.Functions.Worker.Extensions.Http.AspNetCore` 2.1.1, Core Tools 4.13.0, host 4.1051.300.26316: a DTO carrying `[JsonProperty("customer_name")]` binds to `null` on every input path tested while the app stays on *System.Text.Json*, with no diagnostic on any of them. ## Change One file, one added paragraph, nothing removed: note that *Newtonsoft.Json* serialization attributes carried over from the in-process model are ignored by *System.Text.Json* without an error. The paragraph gives the two ways out: replace them with their *System.Text.Json* equivalents, or configure *Newtonsoft.Json* for the layer that handles the payload. ## Notes for review The edited file is an include, `includes/functions-dotnet-migrate-isolated-other-code-changes.md`. It renders inside `articles/azure-functions/migrate-dotnet-to-isolated-model.md`, which is also the file changed by my open PR #128730. The two touch different files and don't conflict, but they land on the same rendered page, so you may want to look at them together. "Configure *Newtonsoft.Json* for the layer that handles the payload" is deliberately unspecific about which layer, because that depends on whether the app uses ASP.NET Core integration. There's a companion change for `articles/azure-functions/dotnet-isolated-process-guide.md` that makes that distinction precise; it's a different file with a different owner, so I'm submitting it separately. Either change stands on its own. * Include Fluent Bit ConfigMap for log collection (#128767) Added Fluent Bit configuration examples for log collection using Azure Files in AKS. and added support limitation. * Document listSecrets access granted by Container Apps built-in roles (#128755) * Document listSecrets access in Container Apps built-in roles Several Container Apps built-in roles define permissions with wildcard patterns that match the listSecrets action, so they grant read access to secret values in plain text even when the role name or description suggests narrower access. - manage-secrets.md: add a 'Permissions for managing secrets' section listing the built-in roles that grant listSecrets, plus a custom role example that omits it. - jobs.md: correct the Permissions section to name the Jobs Contributor and Jobs Operator roles, call out that both grant listSecrets, and fix the custom role action list (executions/read, stop/action, managedEnvironments/read). - security.md: add secrets management best practices covering role review and custom roles. Roles verified against live ARM role definitions and articles/role-based-access-control/built-in-roles/containers.md. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Correct claim that a custom role without listSecrets blocks secret access The job start API accepts a template override that replaces the container image, command, and environment variables for the execution. An identity holding only Microsoft.App/jobs/start/action can therefore run an arbitrary container with the job's secrets injected and read the values from inside it. Omitting listSecrets from a custom role does not prevent this, so the previous guidance was misleading. - jobs.md: replace the vague 'you get access to all the secrets' note with an IMPORTANT callout explaining the override mechanism, and stop presenting the custom role action list as a way to run jobs without secret access. - manage-secrets.md: change the custom role example to a monitor-only role that omits start/action, and add a WARNING covering the start/action escalation path. Verified against the job start REST contract documented in jobs.md and the --image/--command/--env-vars parameters of 'az containerapp job start'. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Clarify Container Apps job permissions and secret access Refine the role guidance after review: - explain that job start can reference retained secrets rather than implying all secrets are injected automatically - qualify managed identity access by container identity availability - link directly to the Jobs - Start REST API - replace Contributor requirements with jobs/start/action - add individual execution read and stop operations to custom roles - correct wildcard and ConnectedEnvironments role descriptions - normalize the permissions table and scope the jobs-specific warning Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address Container Apps permissions review findings Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Clarify Container Apps secret access guidance Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Update articles/container-apps/jobs.md * Update articles/container-apps/jobs.md Co-authored-by: Craig Shoemaker <craigshoemaker@gmail.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Craig Shoemaker <craigshoemaker@gmail.com> * Add FAQ about multiple X-Azure-Ref values (#128749) * Add FAQ about multiple X-Azure-Ref values - question: Why do I see multiple X-Azure-Ref values in my backend application logs when requests pass through Azure Front Door? answer: The X-Azure-Ref value displayed in the client response and Azure Front Door access logs represents the primary request correlation identifier generated by Azure Front Door. Additional X-Azure-Ref values observed only in backend application logs are expected and are internal correlation identifiers generated during request processing within the Azure Front Door platform. These internal identifiers are used by the service for request tracking and diagnostics and don't indicate multiple client requests. * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * docs: remove duplicate 'the' in NSG diagnostics comments (#128783) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * Clarify Prometheus counter visibility (#128772) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 09f5c5be-413a-4b74-b070-c848484e0d73 * docs: fix 'enviroment' typo in Data Factory access strategies (#128774) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'for' in Azure NetApp Files clone FAQ (#128775) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'to' in private link relocation guide (#128776) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in Logic Apps Reassert docs (#128777) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in storage task runs alt-text (#128781) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in WebJobs deploy alt-text (#128780) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'to' in Container Apps volume mount error (#128778) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'to' in Functions identity-based connections (#128779) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in SignalR Front Door alt-text (#128784) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in Site Recovery reprotect guide (#128785) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in Batch upgrade policy note (#128782) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in Planetary Computer ingestion overview (#128786) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in IoT Edge downstream device guide (#128787) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> --------- Co-authored-by: learn-build-service-prod[bot] <113403604+learn-build-service-prod[bot]@users.noreply.github.com> Co-authored-by: Fabian <info@fzankl.de> Co-authored-by: jacobbaek <dubaek@gmail.com> Co-authored-by: Learn Build Service GitHub App <Learn Build Service LearnBuild@microsoft.com> Co-authored-by: Tiago Alves Macambira <tmacam@burocrata.org> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Craig Shoemaker <craigshoemaker@gmail.com> Co-authored-by: Jagan Peddabavi <157447885+Jpeddabavi@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: mrchatam <chatam@proton.me> Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> Co-authored-by: Kelly Shields <kellyshields@microsoft.com> Copilot-Session: 09f5c5be-413a-4b74-b070-c848484e0d73

46bb67c

Document GitHub Copilot modernization for App Service Managed Instance (#320057) * docs: document Copilot Managed Instance workflow Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: ebca454a-718d-4b20-8373-f85118df1f96 * Update articles/migrate/web-app-migration-modernization.md Co-authored-by: learn-build-service-prod-08[bot] <274430765+learn-build-service-prod-08[bot]@users.noreply.github.com> * Update articles/migrate/web-app-migration-modernization.md Co-authored-by: learn-build-service-prod-08[bot] <274430765+learn-build-service-prod-08[bot]@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: learn-build-service-prod-08[bot] <274430765+learn-build-service-prod-08[bot]@users.noreply.github.com> Copilot-Session: ebca454a-718d-4b20-8373-f85118df1f96