> azure-web-application-firewall

Expert knowledge for Azure Web Application Firewall development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when building, debugging, or optimizing Azure Web Application Firewall applications. Not for Azure Application Gateway (use azure-application-gateway), Azure Front Door (use azure-front-door), Azure Firewall (use azure-firewall), Azure DDos Protectio

fetch
$curl "https://skillshub.wtf/MicrosoftDocs/Agent-Skills/azure-web-application-firewall?format=md"
SKILL.mdazure-web-application-firewall

Azure Web Application Firewall Skill

This skill provides expert guidance for Azure Web Application Firewall. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g., L35-L120), use read_file with the specified lines. For categories with file links (e.g., [security.md](security.md)), use read_file on the linked reference file

IMPORTANT for Agent: If metadata.generated_at is more than 3 months old, suggest the user pull the latest version from the repository. If mcp_microsoftdocs tools are not available, suggest the user install it: Installation Guide

This skill requires network access to fetch documentation content:

  • Preferred: Use mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.
  • Fallback: Use fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.

Category Index

CategoryLinesDescription
TroubleshootingL37-L43Diagnosing and fixing common Azure WAF issues on Front Door and Application Gateway, including false positives, blocked requests, rule tuning, and investigating WAF logs.
Best PracticesL44-L52Best practices for configuring, tuning, and hardening Azure WAF on Front Door and Application Gateway, including rule tuning, exclusions, geomatch rules, and deployment security.
Decision MakingL53-L59Guidance on planning and executing migration from legacy WAF configs to full WAF policies, and choosing/upgrading the appropriate Azure WAF managed rulesets.
Architecture & Design PatternsL60-L64Architectural guidance for designing DDoS-resistant web apps using Azure WAF with Front Door, including traffic flow, protection layers, and best-practice deployment patterns.
Limits & QuotasL65-L69Configuring WAF request body and file upload size limits on Application Gateway, including max size settings, constraints, and how to safely adjust them.
SecurityL70-L75Bot protection features and configuration for Application Gateway WAF, plus using Azure Policy to enforce WAF settings, governance, and compliance across resources.
ConfigurationL76-L122Configuring Azure WAF (Front Door & App Gateway): policies, custom/managed rules, rate limiting, geo/IP filters, bot/CAPTCHA, exclusions, logging/scrubbing, and custom block responses.
Integrations & Coding PatternsL123-L133Using WAF with other Azure services: integrating logs with Sentinel/Log Analytics, automating incident response, investigating events, and protecting APIM/Azure OpenAI via Front Door WAF.
DeploymentL134-L139How to deploy and provision Azure Application Gateway WAF v2 using Bicep, ARM templates, or Terraform, including required resources, parameters, and configuration structure.

Troubleshooting

TopicURL
Resolve common Azure Front Door WAF questionshttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-faq
Resolve common Azure Application Gateway WAF issueshttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-waf-faq
Troubleshoot Azure Application Gateway WAF blocking issueshttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/web-application-firewall-troubleshoot

Best Practices

TopicURL
Implement best practices for Front Door WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-best-practices
Tune Azure Front Door WAF rules and exclusionshttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-tuning
Apply best practices for Application Gateway WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/best-practices
Apply geomatch WAF rules to strengthen web app securityhttps://learn.microsoft.com/en-us/azure/web-application-firewall/geomatch-custom-rules-examples
Secure and harden Azure Web Application Firewall deploymentshttps://learn.microsoft.com/en-us/azure/web-application-firewall/secure-web-application-firewall

Decision Making

TopicURL
Migrate Azure Application Gateway WAF configs to full policieshttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/migrate-policy
Plan upgrade from WAF configuration to WAF policyhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/upgrade-ag-waf-policy
Choose and upgrade Azure WAF managed rulesetshttps://learn.microsoft.com/en-us/azure/web-application-firewall/ruleset-support-policy

Architecture & Design Patterns

TopicURL
Design application DDoS protection with Azure WAF and Front Doorhttps://learn.microsoft.com/en-us/azure/web-application-firewall/shared/application-ddos-protection

Limits & Quotas

TopicURL
Configure WAF request and file upload size limits on Application Gatewayhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-waf-request-size-limits

Security

TopicURL
Understand bot protection capabilities on Application Gateway WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/bot-protection-overview
Enforce WAF governance using Azure Policyhttps://learn.microsoft.com/en-us/azure/web-application-firewall/shared/waf-azure-policy

Configuration

TopicURL
Configure CAPTCHA challenges in Azure Front Door WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/captcha-challenge
Configure custom block responses for Front Door WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-configure-custom-response-code
Configure IP restriction rules in Front Door WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-configure-ip-restriction
Create and attach a WAF policy in Azure Front Doorhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-create-portal
Define custom WAF rules for Azure Front Doorhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-custom-rules
Configure Azure Front Door WAF custom and managed ruleshttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-custom-rules-powershell
Configure exclusion lists for Front Door WAF policieshttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-exclusion
Set up WAF exclusion rules on Azure Front Doorhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-exclusion-configure
Configure geo-filtering rules in Azure Front Door WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-geo-filtering
Configure monitoring and logging for Front Door WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-monitor
Enable and configure bot protection in Front Door WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-policy-configure-bot-protection
Configure Azure Front Door WAF policy-level settingshttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-policy-settings
Configure rate limiting policies in Front Door WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-rate-limit
Create and tune WAF rate-limit rules on Front Doorhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-rate-limit-configure
Create a geo-filtering WAF policy with PowerShellhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-tutorial-geo-filtering
Configure log scrubbing on Azure Front Door WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-sensitive-data-protection-configure-frontdoor
Enable sensitive data protection for Front Door WAF logshttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-sensitive-data-protection-frontdoor
Reference for Application Gateway WAF CRS and DRS ruleshttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-crs-rulegroups-rules
Customize Application Gateway WAF rules using Azure CLIhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-customize-waf-rules-cli
Customize Application Gateway WAF rules in Azure portalhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-customize-waf-rules-portal
Customize Application Gateway WAF rules with PowerShellhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-customize-waf-rules-powershell
Configure WAF exclusion lists on Application Gatewayhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-waf-configuration
Configure and analyze Application Gateway WAF metricshttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-waf-metrics
Associate WAF policies with existing Application Gatewayshttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/associate-waf-policy-existing-gateway
Configure bot protection rules for Azure Application Gateway WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/bot-protection
Configure custom block response codes and pages for Application Gateway WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/configure-custom-response-code
Create WAF v2 custom rules with Azure PowerShellhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/configure-waf-custom-rules
Design and apply WAF v2 custom rules on Application Gatewayhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/create-custom-waf-rules
Create and attach WAF policies to Azure Application Gatewayhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/create-waf-policy-ag
Overview of WAF v2 custom rules on Application Gatewayhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/custom-waf-rules-overview
Configure HTTP DDoS ruleset for Application Gateway WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/ddos-ruleset
Configure geomatch custom rules for Application Gateway WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/geomatch-custom-rules
Use Application Gateway WAF Insights dashboardshttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/insights
Configure per-site WAF policies with PowerShellhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/per-site-policies
Understand and scope WAF policies on Application Gatewayhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/policy-overview
Create rate-limiting custom rules for Application Gateway WAF v2https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/rate-limiting-configure
Configure rate limiting for Azure Application Gateway WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/rate-limiting-overview
Upgrade CRS/DRS ruleset versions on Application Gateway WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/upgrade-ruleset-version
Configure sensitive data protection in WAF logshttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/waf-sensitive-data-protection
Set up WAF log scrubbing on Application Gatewayhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/waf-sensitive-data-protection-configure
Enable and manage logging for Azure WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/web-application-firewall-logs
Manage WAF policies centrally with Azure Firewall Managerhttps://learn.microsoft.com/en-us/azure/web-application-firewall/shared/manage-policies
Use JavaScript challenge for bot mitigation in WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/waf-javascript-challenge

Integrations & Coding Patterns

TopicURL
Automate WAF incident response with Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/automated-detection-response-with-sentinel
Protect APIM-hosted APIs with Front Door WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/protect-api-hosted-apim-by-waf
Secure Azure OpenAI endpoints using Front Door WAFhttps://learn.microsoft.com/en-us/azure/web-application-firewall/afds/protect-azure-open-ai
Analyze Application Gateway WAF logs with Log Analyticshttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/log-analytics
Investigate Azure WAF events with Security Copilothttps://learn.microsoft.com/en-us/azure/web-application-firewall/waf-copilot
Detect new web threats using WAF and Sentinelhttps://learn.microsoft.com/en-us/azure/web-application-firewall/waf-new-threat-detection
Integrate Azure WAF logs with Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/web-application-firewall/waf-sentinel

Deployment

TopicURL
Deploy Azure Application Gateway WAF v2 using Bicephttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/quick-create-bicep
Deploy Azure Application Gateway WAF v2 via ARM templatehttps://learn.microsoft.com/en-us/azure/web-application-firewall/ag/quick-create-template
Provision Application Gateway WAF v2 with Terraformhttps://learn.microsoft.com/en-us/azure/web-application-firewall/quickstart-web-application-firewall-terraform

> related_skills --same-repo

> azure-well-architected

Expert guidance for designing, assessing, and optimizing Azure workloads using Azure Well Architected. Covers design review checklists, recommendations, design principles, tradeoffs, service guides, workload patterns, and assessment questions. Use when architecting new solutions, reviewing existing workloads, or applying Well-Architected principles.

> azure-web-pubsub

Expert knowledge for Azure Web PubSub development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when building, debugging, or optimizing Azure Web PubSub applications. Not for Azure SignalR Service (use azure-signalr-service), Azure Event Hubs (use azure-event-hubs), Azure Service Bus (use azure-service-bus), Azure Relay (use azure-relay).

> azure-vpn-gateway

Expert knowledge for Azure VPN Gateway development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when building, debugging, or optimizing Azure VPN Gateway applications. Not for Azure Virtual Network (use azure-virtual-network), Azure Virtual WAN (use azure-virtual-wan), Azure ExpressRoute (use azure-expressroute), Azure Application Gateway (use azure-applica

> azure-vmware-solution

Expert knowledge for Azure VMware Solution development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when building, debugging, or optimizing Azure VMware Solution applications. Not for Azure Virtual Machines (use azure-virtual-machines), Azure Virtual Network (use azure-virtual-network), Azure VPN Gateway (use azure-vpn-gateway), Azure ExpressRoute (use azur

┌ stats

installs/wk0
░░░░░░░░░░
github stars425
██████████
first seenMar 17, 2026
└────────────

┌ repo

MicrosoftDocs/Agent-Skills
by MicrosoftDocs
└────────────

┌ tags

└────────────