The resource containing a WAF's custom and managed rules, linked to an Application Gateway or a Front Door endpoint; it is never attached straight to Azure Firewall or a web app.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains WAF policy in context, with comparison tables and the common traps.
Terms in this definition
- Web Application Firewall
Protection at layer 7 from OWASP Top 10 threats like XSS and SQL injection, available on Application Gateway or Front Door.
- Application Gateway
Layer-7 load balancer deployed per region, offering URL-based routing, TLS offload, cookie-based affinity and an optional WAF.
- Azure Firewall
Stateful network firewall run by Azure as a managed service; it can be placed in Virtual WAN hubs and administered through Firewall Manager.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
Related terms
- Frontend host
In Front Door (classic), the host name, either *.azurefd.net or a custom domain, to which a WAF policy gets linked. Linking it does not filter any traffic by itself.
- Global WAF policy
Azure Front Door's kind of WAF policy, linked to a profile, a route or a domain. Associating it with an application gateway is not possible.
- HTTP listener
Part of an Application Gateway that receives traffic on a set frontend IP, port and protocol, plus a host name when multi-site. A WAF policy can be scoped per site to it.
- New-AzApplicationGatewayFirewallPolicyExclusion
Cmdlet that defines an exclusion from managed rules within an Application Gateway WAF policy.
- Per-site WAF policy
WAF policy attached to a specific HTTP listener on Application Gateway, taking precedence over the gateway's global policy for that site alone.
- Regional WAF policy
Kind of WAF policy used with Application Gateway, created in the same region as the gateway and applied to the whole gateway, a listener or a path. You can create it before the gateway.
- Security policy (Front Door)
In Front Door Standard or Premium, the resource that links a WAF policy to domains, or alternatively to routes or the whole profile.
- Set-AzApplicationGatewayFirewallPolicy
Cmdlet in Az.Network for saving edits to an Application Gateway WAF policy, whether to custom rules, managed rules or policy settings.