[In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door
What the source says
Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request continues to be inspected. Exceptions provide additional flexibility by allowing specific requests to bypass WAF inspection at the rule, rule group, or managed ruleset level. Exceptions can be defined using request URI, remote IP address, or request header name and value, helping customers tune WAF policies more precisely while keeping other protections active. To configure Exceptions, navigate to your WAF policy in the Azure portal, select Managed rules, and then add an exception. Learn more: Application Gateway documentation Front Door documentation
Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont
Why it matters: The change matters because the official source describes: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont
Urgency: Monitor
Next action: Review affected accounts with the customer using the official announcement.
Commercial opportunities
Use the verified change to open a scoped customer conversation.
Technical actions
Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
Does this documented change affect a product or workload in scope?
Risks and objections
The official source does not establish facts beyond the quoted material.
Points to confirm
The effective date is unknown and must be confirmed before scheduling action.
Reading for it_manager_dsi
Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont
Why it matters: The change matters because the official source describes: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont
Urgency: Monitor
Next action: Assess technical dependencies and ownership against the official update.
Commercial opportunities
Offer a scoped technical-readiness assessment if the customer confirms impact.
Technical actions
Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
Does this documented change affect a product or workload in scope?
Risks and objections
The official source does not establish facts beyond the quoted material.
Points to confirm
The effective date is unknown and must be confirmed before scheduling action.
Reading for partner_channel
Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont
Why it matters: The change matters because the official source describes: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont
Urgency: Monitor
Next action: Prepare a source-backed customer conversation and confirm the affected estate.
Commercial opportunities
Qualify a partner-led assessment only after customer scope is confirmed.
Technical actions
Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
Does this documented change affect a product or workload in scope?
Risks and objections
The official source does not establish facts beyond the quoted material.
Points to confirm
The effective date is unknown and must be confirmed before scheduling action.
Reading for sales_manager
Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont
Why it matters: The change matters because the official source describes: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont
Urgency: Monitor
Next action: Review portfolio exposure with account owners using the official source.
Commercial opportunities
Prioritize accounts that confirm affected products or workloads.
Technical actions
Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
Does this documented change affect a product or workload in scope?
Risks and objections
The official source does not establish facts beyond the quoted material.
Points to confirm
The effective date is unknown and must be confirmed before scheduling action.
Evidence and traceability
Each excerpt is linked to the primary source. Current raw version: 448.
Raw capture : 2026-08-26T14:18:57.653130+00:00 — hash 9bb594424bc1e9ff…
Event
[In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request continues to be inspected. Exceptions provide additional flexibility by allowing specific requests to bypass WAF inspection at the rule, rule group, or managed ruleset level. Exceptions can be defined using request URI, remote IP address, or request header name and value, helping customers tune WAF policies more precisely while keeping other protections active. To configure Exceptions, navigate to your WAF policy in the Azure portal, select Managed rules, and then add an exception. Learn more: Application Gateway documentation Front Door documentation
[In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request continues to be inspected. Exceptions provide additional flexibility by allowing specific requests to bypass WAF inspection at the rule, rule group, or managed ruleset level. Exceptions can be defined using request URI, remote IP address, or request header name and value, helping customers tune WAF policies more precisely while keeping other protections active. To configure Exceptions, navigate to your WAF policy in the Azure portal, select Managed rules, and then add an exception. Learn more: Application Gateway documentation Front Door documentation
[In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request continues to be inspected. Exceptions provide additional flexibility by allowing specific requests to bypass WAF inspection at the rule, rule group, or managed ruleset level. Exceptions can be defined using request URI, remote IP address, or request header name and value, helping customers tune WAF policies more precisely while keeping other protections active. To configure Exceptions, navigate to your WAF policy in the Azure portal, select Managed rules, and then add an exception. Learn more: Application Gateway documentation Front Door documentation
[In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request continues to be inspected. Exceptions provide additional flexibility by allowing specific requests to bypass WAF inspection at the rule, rule group, or managed ruleset level. Exceptions can be defined using request URI, remote IP address, or request header name and value, helping customers tune WAF policies more precisely while keeping other protections active. To configure Exceptions, navigate to your WAF policy in the Azure portal, select Managed rules, and then add an exception. Learn more: Application Gateway documentation Front Door documentation
[In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request continues to be inspected. Exceptions provide additional flexibility by allowing specific requests to bypass WAF inspection at the rule, rule group, or managed ruleset level. Exceptions can be defined using request URI, remote IP address, or request header name and value, helping customers tune WAF policies more precisely while keeping other protections active. To configure Exceptions, navigate to your WAF policy in the Azure portal, select Managed rules, and then add an exception. Learn more: Application Gateway documentation Front Door documentation
[In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request continues to be inspected. Exceptions provide additional flexibility by allowing specific requests to bypass WAF inspection at the rule, rule group, or managed ruleset level. Exceptions can be defined using request URI, remote IP address, or request header name and value, helping customers tune WAF policies more precisely while keeping other protections active. To configure Exceptions, navigate to your WAF policy in the Azure portal, select Managed rules, and then add an exception. Learn more: Application Gateway documentation Front Door documentation