Azure WAF: diagnose inconsistent policy enforcement after deployment
A production runbook for separating ARM rollout, WAF associations, rule priority and request variance before a global Application Gateway policy rollback.
Read article
Tag
23 articles connected to this technical signal.
A production runbook for separating ARM rollout, WAF associations, rule priority and request variance before a global Application Gateway policy rollback.
Read articleA production runbook for separating legitimate automation, spoofed identities and hostile bot traffic before changing Azure WAF Bot Manager actions.
Read articleA production runbook for separating file upload limits, request body size, inspection depth, WAF rules and backend rejection before a reversible change.
Read articleA production runbook for qualifying an Azure WAF OWASP/CRS managed rule upgrade with logs, false positives, Detection mode, policy diff, application validation, Prevention decision and rollback.
Read articleA production runbook for qualifying Azure WAF rate limiting with logs, counting key, real clients, false positives, load checks, threshold decision and rollback.
Read articleA production runbook for qualifying an Application Gateway TLS certificate rotation from Key Vault with managed identity, listener checks, WAF evidence, probes, logs, validation and rollback.
Read articleA production runbook for documenting an Azure WAF change with KQL evidence, policy diff, application probes, security validation, merge decision and rollback.
Read articleA short query to isolate rule, field, URI and examples before proposing a targeted WAF exclusion.
Read articleA production runbook for qualifying an Azure WAF policy before switching to Prevention with KQL evidence, change scope, application validation, rollback window and an operable decision.
Read articleA short query to separate unavailable backend, application failure and WAF blocking when Application Gateway returns 502s on a private path.
Read articleQualify a failure across Application Gateway, WAF, internal APIM and a private backend by separating DNS, routing, policy, identity and logs before any fix.
Read articleA short query to see whether a private API request is blocked by Application Gateway WAF, received by APIM or missing from the expected path.
Read articleBuild useful synthetic probes for DNS, TLS, Application Gateway, WAF and Private Endpoint so private Azure paths fail with evidence before production incidents.
Read articleA short query to track synthetic probe failures and separate DNS, TLS, WAF or Application Gateway symptoms on an Azure private path.
Read articleApply a temporary Azure WAF custom rule with priority, KQL evidence, business validation and rollback, without permanently hiding managed-rule signals.
Read articleA short command to list custom rules in an Azure WAF policy with priority, action and type before an urgent change.
Read articleA short KQL query to identify the most blocked URIs by Azure Web Application Firewall on Application Gateway.
Read articleKnow when to add an Azure WAF custom rule to block or allow precise traffic before managed OWASP/CRS rules, without hiding useful security signals.
Read articleMove from a qualified WAF block to a targeted OWASP/CRS exclusion in an Azure Application Gateway policy, with scope, variable, rule, validation and rollback.
Read articleA KQL analysis method to qualify an Azure WAF block, distinguish attack, noise and application false positive, then document the decision before any exclusion.
Read articleBuild useful KQL queries to identify requests blocked by Azure Web Application Firewall on Application Gateway, with action, ruleId, URI, client IP, hostname and time window.
Read articleA diagnostic method for Azure Application Gateway 502 errors that separates DNS resolution, probes, backend settings, TLS, hostnames, certificates and real application behavior.
Read articleAn operational walkthrough for publishing a controlled business application behind Azure Application Gateway with dedicated HTTPS listeners, mutual TLS, a scoped WAF policy, HTTPS backends, and network validation points.
Read article