Maintained with ☕️ by
IcePanel logo
Microsoft Azure logo
Original post

Public Preview: Azure Front Door profile and route level WAF policies

Share

Services

Azure Front Door’s Web Application Firewall (WAF) now supports profile and route level WAF policy associations in public preview. This gives you more flexibility to apply broad baseline protection across an Azure Front Door profile while using targeted policies for specific applications, domains, or routes that need different controls. With this update, you can associate WAF policies at the profile, domain, or route scope. For example, you can use a profile level policy for common protections across all domains in a profile, then apply a route level policy to sensitive paths such as sign-in, checkout, or API routes. This helps reduce policy duplication while still allowing more granular security configuration where it's needed. If multiple WAF policy scopes apply to a request, Azure Front Door uses the most specific policy: a route level policy takes precedence over a domain level policy, and a domain level policy takes precedence over a profile level policy. To get started, create or update an Azure Front Door WAF policy in the Azure portal and choose the associated scope that matches your deployment needs. [Learn more](https://learn.microsoft.com/azure/web-application-firewall/afds/afds-overview).