Protection at layer 7 from OWASP Top 10 threats like XSS and SQL injection, available on Application Gateway or Front Door.
Also called WAF, WAF.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Web Application Firewall in context, with comparison tables and the common traps.
Terms in this definition
- OWASP
Short for Open Web Application Security Project. WAF rule sets are designed to block the critical web application risks this group lists in its OWASP Top 10.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- XSS
A web attack in which harmful scripts are injected into pages that other users then view; a WAF blocks it.
- SQL injection
Smuggling SQL into the input an application accepts. NSGs cannot detect it; WAF managed rule sets, such as those on Application Gateway, stop it at the web tier, and Microsoft Defender for SQL alerts on it.
- Application Gateway
Layer-7 load balancer deployed per region, offering URL-based routing, TLS offload, cookie-based affinity and an optional WAF.
Related terms
- AGWFirewallLogs
Log Analytics table, resource-specific, that stores WAF events from Application Gateway. Front Door uses different tables.
- Application Gateway Basic SKU
Low-traffic Application Gateway v2 SKU that supports header rewrite but omits WAF, mTLS and URL rewrite.
- Application Gateway v1
First-generation Application Gateway SKU, with Standard and WAF tiers and authentication certificates, which retired on 28 April 2026. Gateways already on v2 cannot revert to it.
- Application Gateway WAF tier
Tier of Application Gateway that brings OWASP Core Rule Set protection, now WAF_v2 since the v1 WAF tier retired on 28 April 2026. No WAF is included with the Standard tier.
- Azure Application Gateway
A load balancer for web traffic that works at layer 7, sending HTTP and HTTPS requests to back ends based on host name or URL path. It can also handle TLS termination and run a web application firewall, which Azure Load Balancer cannot since it doesn't read web requests.
- Azure Front Door
Layer-7 global front end that fails over between origins using anycast, terminates TLS, routes requests by URL path and can apply a rate-limiting WAF.
- Azure Load Balancer
Layer-4 load balancer operating within a region, with zone redundancy on the Standard SKU; it has no WAF, doesn't terminate TLS and can't route by URL.
- Bot Manager rule set
WAF managed rules that sort incoming bots into good, bad or unknown categories and apply an action to each.