← Azure projects

Azure · Reference Architecture

Secure Azure App Service PaaS Architecture

Expose only the intended web entry point while App Service reaches data, secrets, and platform dependencies through controlled private network paths.

PlatformAzure
DomainSecurity
LevelAdvanced
Last reviewed2026-09-19
Use whenHost a public or private web application while minimizing direct exposure of application dependencies and controlling inbound and outbound traffic paths.
Key decisionSeparate inbound and outbound patterns
Primary servicesAzure App Service · Azure Front Door · Web Application Firewall
Cost focusApp Service plan
On this page

Building blocks

Azure App ServiceAzure Front DoorWeb Application FirewallVNet IntegrationPrivate EndpointAzure Key VaultAzure SQL Database

Design goal

Host an App Service workload with deliberate inbound exposure, private access to dependencies, controlled outbound routing, and centralized security telemetry.

Architecture

Public traffic can terminate at Azure Front Door/WAF while the application uses App Service networking controls. Outbound dependency access uses VNet Integration and private endpoints where appropriate.

Inbound HTTPSOutbound private accessVNet boundary
Azure regionVirtual networkIntegration subnetPrivate endpoint subnetUsersFront Door+ WAFApp ServicePaaS serviceVNet IntegrationPrivate EndpointsSQL / StorageKey VaultPrivate DNSManaged Identityno stored secretsDiagnosticscentral monitoringHTTPSHTTPSVNet Integrationprivate routeDNSidentity
Inbound HTTPS
Users
Front Door / WAF
App Service
Outbound private access
VNet Integration
Private Endpoints + Private DNS
SQL / Storage / Key Vault

Architecture decisions

Decision

Separate inbound and outbound patterns

Why

Private Endpoint controls private inbound access; VNet Integration provides outbound access from App Service into the virtual network.

Trade-off

The separation gives precise control over exposure and egress, but adds DNS, subnet, routing, and troubleshooting complexity compared with an all-public design.

Decision

Protect the origin

Why

Where required, use a front-door/WAF pattern and restrict direct origin access.

Trade-off

Front-door and WAF controls reduce direct exposure, but add another availability, certificate, routing, and cost layer in front of the application.

Networking

Make the traffic path explicit. Use App Service networking features according to direction: inbound private access with Private Endpoint, outbound VNet access with VNet Integration.

Security

Protect the control and data paths deliberately. Use managed identity, Key Vault, private endpoints, TLS, WAF policy, least-privilege access, and centralized diagnostics.

Availability

Design for the failure domain that must be survived. Use App Service scale-out and zone-redundancy options where supported by the selected plan and region.

Disaster recovery

Treat regional recovery as a separate operating state. For regional DR, replicate application configuration, dependencies, secrets, and data; use global routing only when the recovery design requires it.

Cost drivers

  • App Service plan
  • Front Door/WAF
  • Private Link
  • Key Vault transactions
  • SQL/Storage dependencies
  • logging

Design assumptions

  • Application supports App Service
  • Required outbound destinations are known
  • DNS for private endpoints is planned

Implementation plan

  1. Select an App Service tier that supports the required scale, networking, and zone capabilities in the target region.
  2. Choose the inbound access model—public through Front Door/WAF or private through Private Endpoint—and document how direct origin access is restricted.
  3. Configure VNet Integration for the outbound subnets, routes, and private dependencies the application actually needs.
  4. Create Private Endpoints for selected data and platform services, then configure the required Private DNS zones and links.
  5. Enable Managed Identity for supported service-to-service access and keep unavoidable secrets in Key Vault.
  6. Send application, platform, WAF, and dependency diagnostics to the intended monitoring workspace and test each network path.

Validate the design

  • Confirm the App Service origin cannot be reached through an unintended public path.
  • Verify application and administration paths resolve private endpoints to the expected private addresses.
  • Test application access to every required private dependency and confirm the traffic follows the intended VNet route.
  • Send a controlled request that triggers a WAF/logging event and confirm it appears in the intended monitoring destination.

Architecture basis

Continue a learning path