Configure an application outbound proxy for eDig365 Reporter
Use this guide when eDig365 Reporter must send application outbound HTTP and HTTPS traffic through a proxy. This option is available only with the Customer network integrated deployment profile.
eDig365 Reporter supports an unauthenticated proxy that preserves end-to-end TLS between the application and each destination. Proxy authentication, TLS interception, and customer-provided certificate authorities are not supported at this time.
Decide whether to use an application outbound proxy
Use an application outbound proxy only when your organization requires eDig365 Reporter HTTP and HTTPS requests to be routed through a single point, such as a proxy that applies allow or deny lists.
| Egress mode | Application outbound proxy behavior |
|---|---|
| Direct App Service path | Proxy-aware application traffic uses the proxy. Other public App Service platform traffic uses the direct App Service path. |
| Customer-routed through the virtual network | Proxy-aware application and supported platform traffic use the customer-routed egress path. The proxy must be reachable from the integration subnet. |
The proxy doesn’t route container image pulls or other App Service operations that occur before the container starts. Ensure that the selected image-pull and egress route can reach the registry without relying on the proxy.
Prepare the proxy
Before starting the Marketplace deployment, provide a proxy that meets all of these requirements:
- Uses an HTTP or HTTPS URI with a host and port, such as
http://proxy.internal.example.com:8080. - Doesn’t require authentication and has no credentials in its URI.
- Doesn’t intercept TLS or replace destination certificates.
- Is reachable from the App Service integration subnet.
- Can resolve and establish HTTPS connections to Microsoft Entra, Microsoft Graph, the selected container registry, and Azure Monitor when support telemetry is enabled.
- Has the required firewall rules and route to its public destinations.
Don’t include a path, query string, credentials, or an asterisk in the proxy URI or bypass additions. Validate DNS, TCP connectivity, HTTPS CONNECT tunneling, and destination certificate trust from the customer network before deployment.
Configure Marketplace
- Start the eDig365 Reporter Marketplace deployment and select Customer network integrated.
- Select the required ingress mode and either Direct App Service path or Customer-routed through the virtual network.
- Under Application outbound proxy, select the unauthenticated proxy mode.
- Enter the proxy URI.
- Add only the customer-specific bypass entries that your organization requires. Use comma-separated entries without spaces.
- Complete the remaining network, DNS, registry, and application settings, then select Review + create.
The deployment sets HTTP_PROXY, HTTPS_PROXY, ALL_PROXY, and NO_PROXY for application traffic. After installation, you can update these App Service settings through the Azure portal or Azure CLI. App Service restarts the application when you apply an app-setting change.
Understand bypass entries
The deployment always creates NO_PROXY entries for loopback, link-local and managed-identity endpoints, plus the exact deployed Storage and Key Vault hosts. Customer additions are merged with this product-managed list and can’t replace it.
Use the narrowest matching entry:
| Entry | Matches |
|---|---|
api.internal.example.com |
Only that exact host. |
.internal.example.com |
Subdomains under internal.example.com. |
10.10.10.10 |
Only that IP address. |
Don’t add the deployed Storage, Key Vault, loopback, link-local, or managed-identity endpoints. They are already bypassed so private dependency and platform-local traffic doesn’t traverse the proxy.
Change proxy settings after installation
Update the proxy configuration directly on the App Service when your organization changes its proxy endpoint or customer-specific bypass entries. Keep all four proxy settings consistent.
Azure portal
- Open the eDig365 Reporter App Service in the Azure portal.
- Select Settings > Environment variables > App settings.
- Update
HTTP_PROXY,HTTPS_PROXY, andALL_PROXYto the new unauthenticated proxy URI. Remove all three settings to disable the application outbound proxy. - Preserve
NO_PROXY. When you add customer bypass entries, append them to the existing comma-separated value. Don’t remove the product-managed entries. - Select Apply, then select Apply again on the Environment variables page. App Service restarts automatically.
Azure CLI
Use a secure terminal and replace the placeholder values. The command updates the three proxy settings; it doesn’t change NO_PROXY.
az webapp config appsettings set \
--resource-group <resource-group-name> \
--name <app-service-name> \
--settings HTTP_PROXY="http://proxy.internal.example.com:8080" HTTPS_PROXY="http://proxy.internal.example.com:8080" ALL_PROXY="http://proxy.internal.example.com:8080"
To update NO_PROXY, first copy its current value from the Azure portal or query it with az webapp config appsettings list. Retain the product-managed entries and append only validated, comma-separated customer entries. Applying an app-setting change restarts the application.
Verify after deployment
- Open the App Service in the Azure portal and select Settings > Environment variables.
- Confirm that
HTTP_PROXY,HTTPS_PROXY,ALL_PROXY, andNO_PROXYhave the expected values. Don’t expose or copy any unrelated secret values. - Request the application’s
/api/info/healthendpoint. For private ingress, make the request from an authorized network. - Review App Service logs and your proxy logs or firewall decisions. Confirm that proxy-aware traffic reaches its approved destinations through the proxy.
- Confirm that Storage, Key Vault, and managed identity continue to use their private or platform-local paths and don’t appear in proxy logs.
- Confirm that the container image pulls and the application starts successfully after an App Service restart.
Troubleshoot
| Symptom | First checks |
|---|---|
| Marketplace rejects the proxy URI | Use an HTTP or HTTPS URI containing only a host and port. Remove credentials, a path, query string, and fragment. |
| Application can’t reach Microsoft Entra, Graph, or telemetry | Check proxy DNS, TCP connectivity, HTTPS CONNECT behavior, destination firewall rules, and certificate trust. |
| Application starts but a container image pull fails | Verify the registry’s direct or customer-routed platform path. Image pulls don’t use the application outbound proxy. |
| Storage, Key Vault, or managed identity requests fail | Check private DNS, private endpoint connectivity, and that product-managed NO_PROXY values remain present. |
| The proxy requires credentials or inspects TLS | This configuration isn’t supported. Use an unauthenticated proxy that preserves destination TLS, or don’t configure an application outbound proxy. |
| You need to change the proxy endpoint | Update HTTP_PROXY, HTTPS_PROXY, and ALL_PROXY together in the Azure portal or Azure CLI. Preserve the product-managed NO_PROXY entries, then verify the application after the automatic restart. |
