Ensure function app is integrated with a virtual network
Description
Integrate function apps with a virtual network to enable access to resources in or through a non-internet-routable virtual network.
This recommendation does not apply to function apps created on the consumption hosting plan, which does not support virtual networking.
Rationale
Integrate function apps with a virtual network for increased security and control.
Impact
Additional configuration may be required to ensure that traffic is routed properly.
Audit Procedure
Using Azure Portal
- Go to
App ServicesorFunction App. - Click the name of a function app.
- Under
Settings, clickNetworking. - Under
Outbound traffic configuration, next toVirtual network integration, ensure that a virtual network and subnet name are displayed. - Repeat steps 1-4 for each function app.
Using Azure CLI
Run the following command to list function apps:
az functionapp list
For each function app, run the following command to get the virtual network subnet ID:
az functionapp show --resource-group <resource-group-name> --name <function-app-name> --query "virtualNetworkSubnetId"
Ensure that a virtual network subnet ID is returned.
Using Azure PowerShell
Run the following command to list function apps:
Get-AzFunctionApp
Run the following command to get the function app in a resource group with a given name:
$app = Get-AzFunctionApp -ResourceGroupName <resource-group-name> -Name <function-app-name>
Run the following command to get the virtual network subnet ID:
$app.virtualNetworkSubnetId
Ensure that a virtual network subnet ID is returned. Repeat for each function app.
Expected Result
A virtual network subnet ID should be returned (not null or empty).
Remediation
Using Azure Portal
- Go to
App ServicesorFunction App. - Click the name of a function app.
- Under
Settings, clickNetworking. - Under
Outbound traffic configuration, next toVirtual network integration, clickNot configured. - Click
Add virtual network integration. - Select an existing App Service Plan connection, or select
New connectionand select a subscription, virtual network, and subnet. - Click
Connect. - Repeat steps 1-7 for each function app requiring remediation.
Using Azure CLI
For each function app requiring remediation, run the following command to integrate with a virtual network:
az functionapp vnet-integration add --resource-group <resource-group-name> --name <function-app-name> --vnet <virtual-network-name> --subnet <subnet-name>
Using Azure PowerShell
For each function app requiring remediation, run the following commands to integrate with a virtual network:
Prepare parameters:
$siteName = '<app-name>'
$vNetResourceGroupName = '<virtual-network-resource-group-name>'
$functionAppResourceGroupName = '<function-app-resource-group-name>'
$vNetName = '<virtual-network-name>'
$integrationSubnetName = '<subnet-name>'
$vNetSubscriptionId = '<subscription-guid>'
Check if the subnet is delegated to Microsoft.Web/serverFarms:
$vnet = Get-AzVirtualNetwork -Name $vNetName -ResourceGroupName $vNetResourceGroupName
$subnet = Get-AzVirtualNetworkSubnetConfig -Name $integrationSubnetName -VirtualNetwork $vnet
Get-AzDelegation -Subnet $subnet
Add delegation:
$subnet = Add-AzDelegation -Name "myDelegation" -ServiceName "Microsoft.Web/serverFarms" -Subnet $subnet
Set-AzVirtualNetwork -VirtualNetwork $vnet
Configure virtual network integration:
$subnetResourceId = "/subscriptions/$vNetSubscriptionId/resourceGroups/$vNetResourceGroupName/providers/Microsoft.Network/virtualNetworks/$vNetName/subnets/$integrationSubnetName"
$functionApp = Get-AzResource -ResourceType Microsoft.Web/sites -ResourceGroupName $functionAppResourceGroupName -ResourceName $siteName
$functionApp.Properties.virtualNetworkSubnetId = $subnetResourceId
$functionApp.Properties.vnetRouteAllEnabled = 'true'
$functionApp | Set-AzResource -Force
Default Value
By default, virtual network integration is not configured.
References
- https://learn.microsoft.com/en-us/azure/azure-functions/functions-networking-options
- https://learn.microsoft.com/en-us/azure/app-service/overview-vnet-integration
- https://learn.microsoft.com/en-us/azure/app-service/configure-vnet-integration-enable
- https://learn.microsoft.com/en-us/cli/azure/functionapp
- https://learn.microsoft.com/en-us/powershell/module/az.functions/get-azfunctionapp
Profile
Level 1 | Automated