Azure Container Apps: how to suppress request paths and query strings in built-in authentication logs?

Bill Brainerd 0 Reputation points
2026-09-25T20:43:51.8633333+00:00

I have an active paid Azure Developer support plan and an open technical support request submitted September 23. As of Friday, September 25, I have not received a substantive human engineering response despite three follow-ups.

Please help route this question to an Azure Container Apps authentication engineer. Please also confirm whether this question qualifies for the Developer plan’s prioritized Microsoft Q&A responses and how to associate it with my existing support request. I can provide case identifiers through an appropriate private Microsoft support channel.

Technical issue:

During a nonproduction test using synthetic data, the platform-managed http-auth container logged user-controlled request paths and query strings. We need a supported way to suppress or redact these values at their source while preserving:

  • Microsoft Entra authentication.

HTTP 401 for anonymous requests.

Allowed-audience and group enforcement.

HTTPS.

Operational and security logging without request content.

Evidence:

An unmatched synthetic request returned HTTP 404. Within the bounded test window, aggregate queries found two records containing the synthetic path/query markers in the http-auth stream, in ContainerAppConsoleLogs_CL.Log_s: one request-start record and one request-end record.

The application container had zero matching markers. Its logging already uses fixed route labels and numeric status codes. Raw log messages were not exported.

Requested answer:

Is there a supported ACA-specific configuration or platform fix that prevents these values from being emitted by the built-in authentication container? Please identify the exact property, API version, scope, and dependencies.

If this is unsupported, please provide an explicit product-team determination and a supported alternative architecture that preserves the controls above.

Collection filters, ingestion transformations, retention changes, or query-time masking would not satisfy the requirement to prevent emission at the source.

This is blocking nonproduction validation. We need an engineering answer and a clear support owner.I have an active paid Azure Developer support plan and an open technical support request submitted September 23. As of Friday, September 25, I have not received a substantive human engineering response despite three follow-ups.

Please help route this question to an Azure Container Apps authentication engineer. Please also confirm whether this question qualifies for the Developer plan’s prioritized Microsoft Q&A responses and how to associate it with my existing support request. I can provide case identifiers through an appropriate private Microsoft support channel.

Technical issue:

During a nonproduction test using synthetic data, the platform-managed http-auth container logged user-controlled request paths and query strings. We need a supported way to suppress or redact these values at their source while preserving:

Microsoft Entra authentication.

HTTP 401 for anonymous requests.

Allowed-audience and group enforcement.

HTTPS.

Operational and security logging without request content.

Evidence:

An unmatched synthetic request returned HTTP 404. Within the bounded test window, aggregate queries found two records containing the synthetic path/query markers in the http-auth stream, in ContainerAppConsoleLogs_CL.Log_s: one request-start record and one request-end record.

The application container had zero matching markers. Its logging already uses fixed route labels and numeric status codes. Raw log messages were not exported.

Requested answer:

Is there a supported ACA-specific configuration or platform fix that prevents these values from being emitted by the built-in authentication container? Please identify the exact property, API version, scope, and dependencies.

If this is unsupported, please provide an explicit product-team determination and a supported alternative architecture that preserves the controls above.

Collection filters, ingestion transformations, retention changes, or query-time masking would not satisfy the requirement to prevent emission at the source.

This is blocking nonproduction validation. We need an engineering answer and a clear support owner.

Azure Container Apps
Azure Container Apps

An Azure service that provides a general-purpose, serverless container platform.

0 comments No comments

1 answer

Sort by: Oldest
  1. Rakesh Mishra 11,350 Reputation points Microsoft External Staff Moderator
    2026-09-26T00:43:33.8866667+00:00

    Hi @Bill Brainerd , I had reached out to over Private message and you provided the details.

    Based on the information, the issue was escalated to Product team and they identified there was an issue.

    Product team hotfixed the issue and released it for your region.

    Please check and confirm if issue is resolved. Please let me know if any other questions.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.