The Application Gateway tiers: Standard_v2 supports rewrites but lacks WAF, WAF_v2 adds a WAF, and Basic offers neither URL rewrite nor WAF. Only WAF_v2 can have a WAF policy attached.
Also called Standard_v2, Standard_v2.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Standard V2 in context, with comparison tables and the common traps.
Terms in this definition
- Application Gateway
Layer-7 load balancer deployed per region, offering URL-based routing, TLS offload, cookie-based affinity and an optional WAF.
- Web Application Firewall
Protection at layer 7 from OWASP Top 10 threats like XSS and SQL injection, available on Application Gateway or Front Door.
- WAF V2
Of the Application Gateway tiers, this one brings protection based on the OWASP Core Rule Set; Standard lacks any WAF, and the first-generation WAF tier reached retirement on 28 April 2026.
- Basic
Low-cost Log Analytics table plan where ingestion is cheap but each query is charged per GB and runs at workspace scope. Full KQL and simple log search alerts are supported; standard log search alerts are not.
- URL
The web address of a resource, on which URL-based routing relies.
- WAF policy
The resource containing a WAF's custom and managed rules, linked to an Application Gateway or a Front Door endpoint; it is never attached straight to Azure Firewall or a web app.
Related terms
- Application Gateway v2
Present-day Application Gateway SKU, Standard_v2 or WAF_v2, offering zone redundancy, autoscaling, a static VIP, Key Vault integration and header rewrite. It requires its own subnet, ideally a /24.