Edit

Retirement of TLS 1.0 and TLS 1.1 versions in Azure API Management

APPLIES TO: All API Management tiers

Following the announcement on November 10, 2023, Microsoft is continuing its transition to requiring TLS 1.2 or later for all connections to Azure services. To minimize disruption to customer workloads, several services continue supporting TLS 1.0 and TLS 1.1 versions and complete their transitions by August 31, 2025 when TLS 1.2 or later is required for all connections to Azure services (unless explicitly indicated in service documentation). The list of remaining services is updated as transitions to TLS 1.2 or later complete.

While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions isn't known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. 

Customers using TLS 1.0 or 1.1 should transition their workloads to TLS 1.2 or later versions to ensure uninterrupted connectivity to Azure services. 

For more information about the notice, see Retirement: Update on retirement of TLS 1.0 and TLS 1.1 versions in Azure Services.

To avoid potential service disruptions, confirm that your resources that interact with Azure services are using TLS 1.2 or later. Then:

For more information about the update to TLS 1.2 or later, see solving the TLS 1.0 problem.