Maintained with ☕️ by
IcePanel logo

Generally Available: Default Rule Set 2.2 and updates to ruleset support policy

Share

Services

We are updating the managed ruleset support policy for Azure Web Application Firewall (WAF) following the general availability of Default Rule Set (DRS) 2.2 on Azure Application Gateway and Azure Front Door. This update provides a clearer, more predictable lifecycle for managed rulesets while ensuring customers continue to benefit from the latest security protections. Starting with DRS 2.2, Azure WAF supports the latest three managed ruleset versions (N, N-1, and N-2) at any given time. When a new ruleset version is released, the version that becomes N-3 enters a final one-year support period. During this final year, the N-3 version may receive only critical security updates as needed. With the release of DRS 2.2, the following ruleset versions are entering their final support year ending on February 26, 2027: CRS 3.1 and CRS 3.0 in Azure Application Gateway and DRS 1.2, DRS 1.1 and DRS 1.0 in Azure Front Door. Customers should upgrade to a supported ruleset version to maintain full protection coverage and ongoing improvements, including enhanced detections and reduced false positives. Learn more: * [Application Gateway Azure WAF documentation](https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-crs-rulegroups-rules?tabs=drs22%2Cowasp32 "https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-crs-rulegroups-rules?tabs=drs22%2cowasp32") * [Front Door Azure WAF documentation](https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-drs?tabs=drs22 "https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-drs?tabs=drs22")