0
votes

I understand that Azure Web Apps as a PaaS offering are inherently more secure than if hosting on your own VM ... but does that mean a firewall solution is not required at all?

Azure offers a few solutions, but anything acting as a firewall seems expensive - so we are wondering if we can just do without one.

2

2 Answers

0
votes

Not required as long as you are secured login for sensitive data and enabled CORN rules. For other protections you can definitely add to your subscription like firewall and DDoS protection.

0
votes

It is not required; however, depending on the type of application you are building it is greatly encouraged, if not required by specific industries.

Depending on your architecture and/or approach and if cost is a concern I'd recommend Azure FrontDoor w/ Web Application Firewall (WAF) enabled. This will cover additional security for your application at a reasonable cost as well as potentially server as a Traffic/Manager Load balancer.