Transport Layer Security, the encryption protocol for traffic like HTTPS and Bastion sessions over port 443. On a storage account, minimumTlsVersion fixes the oldest accepted version without opening any network access.
Also called Transport Layer Security.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-5002V0-17.25AZ-900AI-200DP-750SC-900SC-200SC-300AZ-400AZ-802MD-102DP-800ALZ
Each book explains TLS in context, with comparison tables and the common traps.
Terms in this definition
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- HTTPS
Secure HTTP, wrapped in TLS. VCF products serve their web UIs and REST APIs this way on 443.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- Storage account
The top-level resource in Azure Storage, giving a unique namespace for table, queue, file and blob data. Location, performance and kind are set when it is created and cannot change.
- minimumTlsVersion
On a storage account, this property (
TLS1_0,TLS1_1orTLS1_2) causes any request negotiated with a lower TLS version to fail with HTTP 400. Network filtering and blocking plain HTTP are outside its scope.
Related terms
- APIM protocols and ciphers
Blade in API Management for switching TLS/SSL protocols (SSL 3.0, for example) and cipher suites on or off, on the client side and towards backends. By default the minimum is TLS 1.2.
- App Service custom domain
Host name bound to an App Service app once the service has confirmed an asuid TXT record and an A or CNAME record. Serving it over HTTPS also requires binding a TLS certificate.
- Application Gateway
Layer-7 load balancer deployed per region, offering URL-based routing, TLS offload, cookie-based affinity and an optional WAF.
- Azure Bastion
Managed service that lets you open RDP and SSH sessions from the portal over TLS on port 443, so VMs need no public IP. Just-in-time VM access differs in that it opens ports 3389 and 22.
- Azure Firewall Standard
Mid-level Azure Firewall SKU: it filters with application and network rules, can block known-bad addresses using threat intelligence and acts as a DNS proxy. Inspecting TLS traffic and IDPS are Premium-only.
- Azure Front Door
Layer-7 global front end that fails over between origins using anycast, terminates TLS, routes requests by URL path and can apply a rate-limiting WAF.
- Azure Load Balancer
Layer-4 load balancer operating within a region, with zone redundancy on the Standard SKU; it has no WAF, doesn't terminate TLS and can't route by URL.
- Certificate management
Part of VCF Operations fleet management that shows TLS certificates for all VCF components in one place. It warns about expiry, configures CAs, generates CSRs, and replaces or automatically renews certificates.