Maintained with ☕️ by
IcePanel logo

Public Preview: Azure DDoS Protection custom policy

Share

Services

Azure DDoS Protection custom policy is now in public preview. This capability provides per-resource control over DDoS mitigation thresholds for protected Standard Load Balancer frontend IP configurations. Customers can configure fixed inbound detection thresholds for TCP, UDP, and TCP SYN traffic. Thresholds can be set from 50,000 to 2,000,000 packets per second, helping customers account for predictable or unusual traffic patterns, including planned launches, seasonal peaks, gaming events, and sustained high-volume workloads. When a custom threshold is configured for a protocol, Azure uses that threshold instead of adaptive auto-tuning for that protocol. Protocols without a custom threshold continue to use Azure DDoS Protection’s adaptive auto-tuning. During public preview, customers can create and manage Custom Policy through the Azure portal, Azure CLI, Azure Resource Manager templates, and the REST API. Custom policy currently supports inbound traffic for Standard Load Balancer frontend IP configurations. Regional availability is limited during the preview. Learn more: * [Read the custom policy overview](https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-custom-policy-overview) * [Manage custom policy using the Azure portal](https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-custom-policy-portal) * [Manage custom policy using Azure CLI](https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-custom-policy-cli) * [Deploy custom policy using an ARM template](https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-custom-policy-template)