I want to use the Azure Application Gateway in FIPS mode for compliance with FIPS 140-2. The only version of Application Gateway that supports FIPS seems to be the V1 version. This is being retired in 2026. What alternatives are there for securing traffic using FIPS standards when the Application Gateway v1 is gone? I prefer using Azure if possible.
1 Answer
You can't get this from Azure. You have to purchase a FIPS validated SSL and upload it to your keyvault in Azure. App Gateway V2 and KeyVault use are required. The references I found are vague answers. Microsoft has FIPS validated modules for their services and resources, but you have to bring your own when you establish your network in their system.