The OWASP Core Rule Set, on which the Application Gateway WAF bases its rules.
Also called Core Rule Set.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains CRS in context, with comparison tables and the common traps.
Terms in this definition
- OWASP
Short for Open Web Application Security Project. WAF rule sets are designed to block the critical web application risks this group lists in its OWASP Top 10.
- Application Gateway
Layer-7 load balancer deployed per region, offering URL-based routing, TLS offload, cookie-based affinity and an optional WAF.
- Web Application Firewall
Protection at layer 7 from OWASP Top 10 threats like XSS and SQL injection, available on Application Gateway or Front Door.
Related terms
- Application Gateway WAF tier
Tier of Application Gateway that brings OWASP Core Rule Set protection, now WAF_v2 since the v1 WAF tier retired on 28 April 2026. No WAF is included with the Standard tier.
- DRS
The Default Rule Set, Microsoft's managed WAF rules that succeed OWASP CRS and defend against XSS, SQL injection and other frequent attacks. Single rules may be overridden or switched off.
- Rule 920300
Protocol-enforcement rule in the OWASP CRS triggered by requests lacking an Accept header, which get a 403 in Prevention mode. Exclusions cannot help with an absent header, so either send the header or disable the rule.
- WAF V2
Of the Application Gateway tiers, this one brings protection based on the OWASP Core Rule Set; Standard lacks any WAF, and the first-generation WAF tier reached retirement on 28 April 2026.