ChannelPulse

[In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door

Vendor
Microsoft
Product
Microsoft Azure
Type
Security
Announcement date
2026-07-07
Effective date
Date not published
Impact
Affected

In brief

[In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door

What the source says

Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request continues to be inspected. Exceptions provide additional flexibility by allowing specific requests to bypass WAF inspection at the rule, rule group, or managed ruleset level. Exceptions can be defined using request URI, remote IP address, or request header name and value, helping customers tune WAF policies more precisely while keeping other protections active. To configure Exceptions, navigate to your WAF policy in the Azure portal, select Managed rules, and then add an exception. Learn more: Application Gateway documentation Front Door documentation

Read the primary source

Reading for commercial_account_manager

Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont

Why it matters: The change matters because the official source describes: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont

Urgency: Monitor

Next action: Review affected accounts with the customer using the official announcement.

Commercial opportunities

Technical actions

Questions to ask the customer

Risks and objections

Points to confirm

Reading for it_manager_dsi

Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont

Why it matters: The change matters because the official source describes: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont

Urgency: Monitor

Next action: Assess technical dependencies and ownership against the official update.

Commercial opportunities

Technical actions

Questions to ask the customer

Risks and objections

Points to confirm

Reading for partner_channel

Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont

Why it matters: The change matters because the official source describes: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont

Urgency: Monitor

Next action: Prepare a source-backed customer conversation and confirm the affected estate.

Commercial opportunities

Technical actions

Questions to ask the customer

Risks and objections

Points to confirm

Reading for sales_manager

Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont

Why it matters: The change matters because the official source describes: [In preview] Public Preview: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure Web Application Firewall (WAF) helps protect your web applications from common threats and attacks. In some cases, WAF may block requests that are safe and expected for your application. Existing exclusions help reduce false positives by omitting specific request attributes, such as headers, cookies, query string arguments, or body fields, from WAF evaluation while the rest of the request cont

Urgency: Monitor

Next action: Review portfolio exposure with account owners using the official source.

Commercial opportunities

Technical actions

Questions to ask the customer

Risks and objections

Points to confirm

Evidence and traceability

Each excerpt is linked to the primary source. Current raw version: 448.

Back to the public feed