WAF rules you define yourself, of match or rate-limit type, that are processed ahead of managed rules and can test conditions like geo-location, IP, headers or URI.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains WAF custom rules in context, with comparison tables and the common traps.
Terms in this definition
- Web Application Firewall
Protection at layer 7 from OWASP Top 10 threats like XSS and SQL injection, available on Application Gateway or Front Door.
- DEFINE
An optional keyword at the start of a DAX query, placed before the first EVALUATE, for declaring things such as measures and variables that exist only for that query. A measure declared this way replaces a model measure with the same name just while the query runs.
- MATCH
Used in WHERE when querying SQL Graph, it describes how to walk from node to node through edge tables, with patterns written like p1-(f1)->p2.
- Test conditions
Rules added to a SQL Server unit test action to judge its outcome, for example Row Count, Scalar Value, Expected Schema or Data Checksum. Freshly created tests include one marked Inconclusive.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- URI
Identifies a resource as a string; examples include the address of a Key Vault secret and the queue service address Functions connections rely on.
Related terms
- Geomatch
An operator for WAF custom rules that compares the client's country or region (
RemoteAddr) so traffic can be allowed or blocked based on geography. - IPMatch
An operator for WAF custom rules that compares the client's IP with a list of addresses or CIDR ranges.
- RequestHeader
Match variable for WAF custom rules that examines a particular request header by name, such as X-Azure-FDID.