Of the Application Gateway tiers, this one brings protection based on the OWASP Core Rule Set; Standard lacks any WAF, and the first-generation WAF tier reached retirement on 28 April 2026.
Also called WAF_v2, WAF_v2.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains WAF V2 in context, with comparison tables and the common traps.
Terms in this definition
- Application Gateway
Layer-7 load balancer deployed per region, offering URL-based routing, TLS offload, cookie-based affinity and an optional WAF.
- OWASP
Short for Open Web Application Security Project. WAF rule sets are designed to block the critical web application risks this group lists in its OWASP Top 10.
- CRS
The OWASP Core Rule Set, on which the Application Gateway WAF bases its rules.
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
- Web Application Firewall
Protection at layer 7 from OWASP Top 10 threats like XSS and SQL injection, available on Application Gateway or Front Door.
- Archive
Offline access tier for blobs, cheapest to store yet dearest to access. Reading a blob means rehydrating it first, which can take as long as 15 hours.
Related terms
- Application Gateway Ingress Controller
Add-on for AKS that reads Kubernetes Ingress resources and sets up an Application Gateway, WAF v2 included, to match them.
- Application Gateway v2
Present-day Application Gateway SKU, Standard_v2 or WAF_v2, offering zone redundancy, autoscaling, a static VIP, Key Vault integration and header rewrite. It requires its own subnet, ideally a /24.
- Application Gateway WAF tier
Tier of Application Gateway that brings OWASP Core Rule Set protection, now WAF_v2 since the v1 WAF tier retired on 28 April 2026. No WAF is included with the Standard tier.
- Standard V2
The Application Gateway tiers: Standard_v2 supports rewrites but lacks WAF, WAF_v2 adds a WAF, and Basic offers neither URL rewrite nor WAF. Only WAF_v2 can have a WAF policy attached.