How to Create a Web Application Firewall policies (WAF) in Microsoft azure.

Azure Web Application Firewall (WAF)  is a cloud-native service that protects your web applications from bot attacks and common web vulnerabilities such as SQL injection and cross-site scripting.

Web Application Firewall Policies contain all the WAF settings and configurations. This includes exclusions, custom rules, managed rules, and so on. These policies are then associated to an application gateway (global), a listener (per-site), or a path-based rule (per-URI) for them to take effect.


  • Login to Azure portal.
  • Click on All Services.
  • Select Web Application Firewall policies (WAF).




  • Click on Create option.



  • On Basics tab provide the following values:-


  • Policy for: Select  Policy such as Global WAF,Regional WAF or Azure CDN as per requirement.
  • Subscription: An Azure subscription grants you access to Azure services.
  • Resource group name: A resource group is a collection of resources.
  • Provide Policy name.
  • A WAF policy can be either enabled or disabled. If disabled, the WAF policy will not be applied to any web sites.
  • Click on Policy settings.




  • At Policy Settings WAF policy can be either Detection or Prevention mode. In Detection mode WAF does not block any requests and In Prevention mode requests that match rules that are defined in Default Rule Set (DRS) are blocked and logged at WAF logs.
  • Provide the specifies parts of incoming requests to exclude.
  • Provide the max request body size in KB.
  • Provide the max file upload size in MB.
  • Then, Click on Managed rules.


Fig.5Fig. 6


  • At managed rules window provide the managed rule set name.
  • Click on Expand all rule & Select all the required rules.
  • Then click on Custom rules.




  • At custom rules click on Add custom rule.




  • At Add custom rule provide the Custom rule name,Priority & Set the conditions(If condition is match then block the requests).
  • Click on Add.
  • Then click on Next Association.





  • At Association click on Add association.




  • Associate the WAF policy with a specific application gateway,listener or route path.
  • Then click on Tags.




  • On Tags Tab provide the tag name and value for Web Application Firewall policy.
  • Click Next on Review + Create.




  • If you get a message “Validation passed”.
  • Then click on Create.



  • After some time, you will see a message as “Your deployment is ready”.
  • Click on “Go to resources” & You can see that the Web Application Firewall policy is there with the name we provide.


Leave a Reply