I have an active paid Azure Developer support plan and an open technical support request submitted September 23. As of Friday, September 25, I have not received a substantive human engineering response despite three follow-ups.
Please help route this question to an Azure Container Apps authentication engineer. Please also confirm whether this question qualifies for the Developer plan’s prioritized Microsoft Q&A responses and how to associate it with my existing support request. I can provide case identifiers through an appropriate private Microsoft support channel.
Technical issue:
During a nonproduction test using synthetic data, the platform-managed http-auth container logged user-controlled request paths and query strings. We need a supported way to suppress or redact these values at their source while preserving:
- Microsoft Entra authentication.
HTTP 401 for anonymous requests.
Allowed-audience and group enforcement.
HTTPS.
Operational and security logging without request content.
Evidence:
An unmatched synthetic request returned HTTP 404. Within the bounded test window, aggregate queries found two records containing the synthetic path/query markers in the http-auth stream, in ContainerAppConsoleLogs_CL.Log_s: one request-start record and one request-end record.
The application container had zero matching markers. Its logging already uses fixed route labels and numeric status codes. Raw log messages were not exported.
Requested answer:
Is there a supported ACA-specific configuration or platform fix that prevents these values from being emitted by the built-in authentication container? Please identify the exact property, API version, scope, and dependencies.
If this is unsupported, please provide an explicit product-team determination and a supported alternative architecture that preserves the controls above.
Collection filters, ingestion transformations, retention changes, or query-time masking would not satisfy the requirement to prevent emission at the source.
This is blocking nonproduction validation. We need an engineering answer and a clear support owner.I have an active paid Azure Developer support plan and an open technical support request submitted September 23. As of Friday, September 25, I have not received a substantive human engineering response despite three follow-ups.
Please help route this question to an Azure Container Apps authentication engineer. Please also confirm whether this question qualifies for the Developer plan’s prioritized Microsoft Q&A responses and how to associate it with my existing support request. I can provide case identifiers through an appropriate private Microsoft support channel.
Technical issue:
During a nonproduction test using synthetic data, the platform-managed http-auth container logged user-controlled request paths and query strings. We need a supported way to suppress or redact these values at their source while preserving:
Microsoft Entra authentication.
HTTP 401 for anonymous requests.
Allowed-audience and group enforcement.
HTTPS.
Operational and security logging without request content.
Evidence:
An unmatched synthetic request returned HTTP 404. Within the bounded test window, aggregate queries found two records containing the synthetic path/query markers in the http-auth stream, in ContainerAppConsoleLogs_CL.Log_s: one request-start record and one request-end record.
The application container had zero matching markers. Its logging already uses fixed route labels and numeric status codes. Raw log messages were not exported.
Requested answer:
Is there a supported ACA-specific configuration or platform fix that prevents these values from being emitted by the built-in authentication container? Please identify the exact property, API version, scope, and dependencies.
If this is unsupported, please provide an explicit product-team determination and a supported alternative architecture that preserves the controls above.
Collection filters, ingestion transformations, retention changes, or query-time masking would not satisfy the requirement to prevent emission at the source.
This is blocking nonproduction validation. We need an engineering answer and a clear support owner.