{"id":9580,"date":"2025-02-20T09:20:50","date_gmt":"2025-02-20T17:20:50","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/cosmosdb\/?p=9580"},"modified":"2025-03-03T09:49:54","modified_gmt":"2025-03-03T17:49:54","slug":"moving-to-tls-1-2-for-azure-cosmos-db-ensuring-secure-connections","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/cosmosdb\/moving-to-tls-1-2-for-azure-cosmos-db-ensuring-secure-connections\/","title":{"rendered":"Moving to TLS 1.2 for Azure Cosmos DB: Ensuring Secure Connections"},"content":{"rendered":"<p><span class=\"TextRun SCXW200322625 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun CommentStart SCXW200322625 BCX8\">Security and reliability are at the core of modern cloud applications. To strengthen data protection and align with industry best practices, we encourage all Azure Cosmos DB customers to transition to <\/span><\/span><a class=\"Hyperlink SCXW200322625 BCX8\" href=\"https:\/\/learn.microsoft.com\/azure\/cosmos-db\/self-serve-minimum-tls-enforcement\" target=\"_blank\" rel=\"noreferrer noopener\"><span class=\"FieldRange SCXW200322625 BCX8\"><span class=\"TextRun Underlined SCXW200322625 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun CommentStart SCXW200322625 BCX8\" data-ccp-charstyle=\"Hyperlink\">TLS 1.2<\/span><\/span><\/span><\/a><span class=\"TextRun SCXW200322625 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW200322625 BCX8\">.<\/span><span class=\"NormalTextRun SCXW200322625 BCX8\"> This post explains why this change is important, how to make the transition, and the benefits it brings to your applications.<\/span><\/span><\/p>\n<h4><span class=\"TextRun SCXW167852154 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW167852154 BCX8\" data-ccp-parastyle=\"heading 2\">Why Move to TLS 1.2?<\/span><\/span><span class=\"EOP SCXW167852154 BCX8\" data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h4>\n<p><span class=\"TextRun SCXW76837811 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW76837811 BCX8\">Transport Layer Security (TLS) is a critical <\/span><span class=\"NormalTextRun SCXW76837811 BCX8\">component<\/span><span class=\"NormalTextRun SCXW76837811 BCX8\"> in securing data transmitted over networks. TLS 1.2 offers enhanced security features compared to its predecessors, TLS 1.0 and 1.1. By moving to TLS 1.2<\/span><span class=\"NormalTextRun SCXW76837811 BCX8\"> or later<\/span><span class=\"NormalTextRun SCXW76837811 BCX8\">, you ensure that your data is protected with the latest encryption standards<\/span><span class=\"NormalTextRun SCXW76837811 BCX8\">, including perfect forward secrecy and stronger cipher suites.<\/span><\/span><span class=\"TextRun SCXW76837811 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW76837811 BCX8\">\u202f<\/span><\/span><span class=\"EOP SCXW76837811 BCX8\" data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h4><span class=\"TextRun SCXW163544938 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW163544938 BCX8\" data-ccp-parastyle=\"heading 2\">Current Situation<\/span><\/span><span class=\"EOP SCXW163544938 BCX8\" data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h4>\n<p><span class=\"TextRun SCXW76830735 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW76830735 BCX8\">Currently, Azure Cosmos DB allows the use of TLS versions lower than 1.2. However, to enhance security, we recommend that all customers enforce TLS 1.2 on their <\/span><span class=\"NormalTextRun SCXW76830735 BCX8\">Azure <\/span><span class=\"NormalTextRun SCXW76830735 BCX8\">Cosmos DB accounts. This change is crucial as it aligns with industry best practices and ensures that your data <\/span><span class=\"NormalTextRun SCXW76830735 BCX8\">remains<\/span><span class=\"NormalTextRun SCXW76830735 BCX8\"> secure.<\/span><\/span><\/p>\n<h4><span class=\"TextRun SCXW210614121 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW210614121 BCX8\" data-ccp-parastyle=\"heading 2\">Challenges<\/span><\/span><\/h4>\n<p><span class=\"TextRun SCXW23305449 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW23305449 BCX8\">We understand that a <\/span><span class=\"NormalTextRun SCXW23305449 BCX8\">significant number<\/span><span class=\"NormalTextRun SCXW23305449 BCX8\"> of <\/span><span class=\"NormalTextRun SCXW23305449 BCX8\">Azure <\/span><span class=\"NormalTextRun SCXW23305449 BCX8\">Cosmos DB customers still use TLS versions lower than 1.2. <\/span><span class=\"NormalTextRun SCXW23305449 BCX8\">S<\/span><span class=\"NormalTextRun SCXW23305449 BCX8\">udden enforcement of TLS 1.2 could lead to disruptions in your applications. Therefore, we are implementing a phased approach to minimize any potential impact.<\/span><\/span><\/p>\n<h4><span class=\"TextRun SCXW51469335 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW51469335 BCX8\" data-ccp-parastyle=\"heading 2\">Proposed Solution<\/span><\/span><\/h4>\n<p><span class=\"TextRun SCXW154834068 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW154834068 BCX8\">Use the <a href=\"https:\/\/ms.portal.azure.com\/#view\/AppInsightsExtension\/UsageNotebookBlade\/ComponentId\/Azure%20Advisor\/ConfigurationId\/community-Workbooks%2FAzure%20Advisor%2FAzureServiceRetirement\/Type\/workbook\/WorkbookTemplateName\/Service%20Retirement%20(Preview)\">Service Retirement Workbook<\/a> to monitor your Azure Cosmos DB accounts with less than TLS 1.2. To address these challenges, <\/span><span class=\"NormalTextRun SCXW154834068 BCX8\">you can use our self-serve feature. <\/span><span class=\"NormalTextRun SCXW154834068 BCX8\">This allows you to set the <\/span><span class=\"NormalTextRun SCXW154834068 BCX8\">minimum<\/span><span class=\"NormalTextRun SCXW154834068 BCX8\"> TLS version for your <\/span><span class=\"NormalTextRun SCXW154834068 BCX8\">Azure <\/span><span class=\"NormalTextRun SCXW154834068 BCX8\">Cosmos DB accounts through the Azure portal. By doing so, you can gradually transition to TLS 1.2 without disrupting your existing workflows.<\/span><\/span><\/p>\n<h4 aria-level=\"2\"><span data-contrast=\"none\">Implementation<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h4>\n<p><span data-contrast=\"auto\">Starting with the 2022-11-15 API version of the Azure Cosmos DB Resource Provider API, a new property called\u202f<\/span><span data-contrast=\"auto\"><span style=\"font-family: terminal, monaco, monospace;\">minimalTlsVersion<\/span>\u202f<\/span><span data-contrast=\"auto\">is available for every Azure Cosmos DB database account.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This property accepts values Tls12 and above, with the default value for new accounts set to\u202fTls12.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h4 aria-level=\"2\"><span data-contrast=\"none\">Important Dates<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h4>\n<ul>\n<li><span data-contrast=\"auto\">Starting August 31, 2025, all <a href=\"https:\/\/aka.ms\/set-tls\">Azure Cosmos DB database accounts must use TLS 1.2 or higher<\/a>. Support for TLS 1.0 and 1.1 will be discontinued.<\/span><\/li>\n<\/ul>\n<div>\n<ul>\n<li>Effective March 31, 2025, <a href=\"https:\/\/aka.ms\/cosmosdbtls13\">support for TLS 1.3 will be enabled for Azure Cosmos DB<\/a>.<\/li>\n<\/ul>\n<\/div>\n<h4 aria-level=\"2\"><span data-contrast=\"none\">Steps to Set Minimal TLS Protocol<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h4>\n<p><span data-contrast=\"auto\">Setting the minimum TLS protocol for your Azure Cosmos DB accounts is straightforward:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ol>\n<li data-leveltext=\"%1.\" data-font=\"\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Navigate to the Azure portal<\/span><\/b><span data-contrast=\"auto\">: Go to your Azure Cosmos DB account settings<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Select Connectivity from the Networking\u00a0<\/span><\/b><\/li>\n<li data-leveltext=\"%1.\" data-font=\"\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Select the desired TLS version<\/span><\/b><span data-contrast=\"auto\"><span data-contrast=\"auto\">:\u00a0 Choose 1.2 or higher.<\/span><\/span><span data-ccp-props=\"{}\"><span data-ccp-props=\"{}\"><a href=\"https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-content\/uploads\/sites\/52\/2025\/02\/networkScreen.png\"><img decoding=\"async\" class=\"aligncenter wp-image-9603\" src=\"https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-content\/uploads\/sites\/52\/2025\/02\/networkScreen-300x286.png\" alt=\"Image showing how to configure tls version\" width=\"508\" height=\"485\" srcset=\"https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-content\/uploads\/sites\/52\/2025\/02\/networkScreen-300x286.png 300w, https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-content\/uploads\/sites\/52\/2025\/02\/networkScreen-1024x976.png 1024w, https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-content\/uploads\/sites\/52\/2025\/02\/networkScreen-768x732.png 768w, https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-content\/uploads\/sites\/52\/2025\/02\/networkScreen-24x24.png 24w, https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-content\/uploads\/sites\/52\/2025\/02\/networkScreen.png 1418w\" sizes=\"(max-width: 508px) 100vw, 508px\" \/><\/a><\/span><\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Save your changes<\/span><\/b><span data-contrast=\"auto\">: Ensure that your settings are updated and applied.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ol>\n<h4 aria-level=\"2\"><span data-contrast=\"none\">Conclusion<\/span><\/h4>\n<p><span data-contrast=\"auto\">Transitioning to TLS 1.2 or higher is a crucial step in securing your Azure Cosmos DB accounts. By following the steps outlined in this blog post, you can ensure that your data remains protected with the latest encryption standards. We are committed to supporting you through this transition and are here to help with any questions or concerns you may have.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Leave a review<\/span><\/h2>\n<p><span data-contrast=\"auto\">Tell us about your Azure Cosmos DB experience! Leave a review on PeerSpot and we\u2019ll gift you $50. <\/span><a href=\"https:\/\/peerspotdotcom.my.site.com\/proReviews\/?SalesOpportunityProduct=00kPy000004TKXJIA4&amp;productPeerspotNumber=30881&amp;CalendlyAccount=peerspot&amp;CalendlyFormLink=peerspot-product-reviews-ps-gc-vi-sf-50&amp;giftCard=50\"><span data-contrast=\"none\">Get started here<\/span><\/a><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2><span data-contrast=\"none\">About Azure Cosmos DB<\/span><\/h2>\n<p><span data-contrast=\"none\">Azure Cosmos DB is a fully managed and serverless NoSQL and vector database for modern app development, including AI applications. With its SLA-backed speed and availability as well as instant dynamic scalability, it is ideal for real-time NoSQL and MongoDB applications that require high performance and distributed computing over massive volumes of NoSQL and vector data.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335557856&quot;:2039583,&quot;335559739&quot;:360,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/cosmos.azure.com\/try\/\"><span data-contrast=\"none\">Try Azure Cosmos DB for free here.<\/span><\/a><span data-contrast=\"none\"> To stay in the loop on Azure Cosmos DB updates, follow us on <\/span><a href=\"https:\/\/twitter.com\/AzureCosmosDB\"><span data-contrast=\"none\">X<\/span><\/a><span data-contrast=\"none\">, <\/span><a href=\"https:\/\/aka.ms\/AzureCosmosDBYouTube\"><span data-contrast=\"none\">YouTube<\/span><\/a><span data-contrast=\"none\">, and <\/span><a href=\"https:\/\/www.linkedin.com\/company\/azure-cosmos-db\/\"><span data-contrast=\"none\">LinkedIn<\/span><\/a><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335557856&quot;:2039583,&quot;335559739&quot;:360,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security and reliability are at the core of modern cloud applications. To strengthen data protection and align with industry best practices, we encourage all Azure Cosmos DB customers to transition to TLS 1.2. This post explains why this change is important, how to make the transition, and the benefits it brings to your applications. Why [&hellip;]<\/p>\n","protected":false},"author":72078,"featured_media":5308,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[14,667],"tags":[499,1934,1591],"class_list":["post-9580","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-core-sql-api","category-security","tag-azure-cosmos-db","tag-network","tag-tls"],"acf":[],"blog_post_summary":"<p>Security and reliability are at the core of modern cloud applications. To strengthen data protection and align with industry best practices, we encourage all Azure Cosmos DB customers to transition to TLS 1.2. This post explains why this change is important, how to make the transition, and the benefits it brings to your applications. Why [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-json\/wp\/v2\/posts\/9580","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-json\/wp\/v2\/users\/72078"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-json\/wp\/v2\/comments?post=9580"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-json\/wp\/v2\/posts\/9580\/revisions"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-json\/wp\/v2\/media?parent=9580"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-json\/wp\/v2\/categories?post=9580"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/cosmosdb\/wp-json\/wp\/v2\/tags?post=9580"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}