Short for Open Web Application Security Project. WAF rule sets are designed to block the critical web application risks this group lists in its OWASP Top 10.
Also called Open Web Application Security Project.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500SC-900
Each book explains OWASP in context, with comparison tables and the common traps.
Terms in this definition
- Web Application Firewall
Protection at layer 7 from OWASP Top 10 threats like XSS and SQL injection, available on Application Gateway or Front Door.
Related terms
- Application Gateway WAF tier
Tier of Application Gateway that brings OWASP Core Rule Set protection, now WAF_v2 since the v1 WAF tier retired on 28 April 2026. No WAF is included with the Standard tier.
- CRS
The OWASP Core Rule Set, on which the Application Gateway WAF bases its rules.
- DRS
The Default Rule Set, Microsoft's managed WAF rules that succeed OWASP CRS and defend against XSS, SQL injection and other frequent attacks. Single rules may be overridden or switched off.
- Managed rule set
Collection of WAF rules maintained by Azure, such as OWASP CRS/DRS and bot rules, that look for attack signatures in request content. Filtering by rate, geography or client address is not something they do.
- OWASP Top 10 dashboard
Highlights which assets in Defender EASM are vulnerable to the top web application risks named by OWASP, such as injection or broken access control.
- Rule 920300
Protocol-enforcement rule in the OWASP CRS triggered by requests lacking an Accept header, which get a 403 in Prevention mode. Exclusions cannot help with an absent header, so either send the header or disable the rule.
- WAF V2
Of the Application Gateway tiers, this one brings protection based on the OWASP Core Rule Set; Standard lacks any WAF, and the first-generation WAF tier reached retirement on 28 April 2026.