Generally Available: HTTP header insertion in Azure Firewall
Share
Services
Azure Firewall now supports HTTP header insertion, enabling organizations to add or overwrite HTTP/HTTPS requestheaders directly from Azure Firewall application rules. This capability helps customers enforce security controls, support tenant restriction scenarios, integrate with backend services, and simplify application access management without relying on third-party proxies or on-premises infrastructure.
The feature is especially useful for scenarios such as Microsoft Entra tenant restrictions, Azure Virtual Desktop, VDI, SaaS access control, and enterprise egress filtering. By enabling header insertion natively in Azure Firewall, customers can reduce proxy dependencies, avoid routing traffic back on premises solely for header injection, and improve operational efficiency.
HTTP header insertion is supported in Azure Firewall Premium for HTTP traffic and HTTPS traffic decrypted using TLS Inspection. In Standard and Basic SKUs, it is supported for HTTP traffic. The feature can be configured through Azure Portal, Azure CLI, PowerShell, REST APIs, Terraform, and Azure Firewall Draft + Deploy.
[Learn more](https://learn.microsoft.com/en-us/azure/firewall/configure-http-header-insertion?tabs=portal).