More Info:

Ensure that FTP access is disabled for your Azure App Services web applications.

Risk Level

Medium

Address

Security

Compliance Standards

Triage and Remediation

Remediation

To remediate the misconfiguration of disabling plain FTP deployment in AZURE, please follow the below steps:

  1. Log in to the AZURE portal (https://portal.azure.com/).

  2. Select the App Service that you want to remediate.

  3. Click on the “Deployment Center” option from the left-hand side menu.

  4. Select the “FTP” option under the “Deployment method” section.

  5. Click on the “FTP Access” option.

  6. In the “FTP Access” window, select the “FTP” option and click on the “Save” button.

  7. Now, select the “FTP/S (SSL)” option and click on the “Save” button.

  8. Click on the “Save” button in the “Deployment Center” window to save the changes.

  9. Now, plain FTP deployment is disabled, and only secure FTP/S (SSL) is enabled for the selected App Service.

Note: It is recommended to use secure FTP/S (SSL) for deployment to ensure that the data is encrypted during transmission.