Increase security, reduce false positives, and improve performance with the Azure Web Application Firewall detection engine combined with updated rule sets.
Deploy easily with no additional software agent required
Centrally define and customize rules to meet your security requirements, then apply them to protect all your web apps.
Get insight into security and analytics
Combine Microsoft Sentinel with Azure Web Application Firewall to easily break down and view your WAF data.
Enforce organizational compliance at scale
Use Azure Policy to help enforce organizational standards and assess compliance at scale for Web Application Firewall resources.
Improve security and performance at the edge
Gain advanced security, scalability, and accelerated delivery of apps, files, and content using Azure Front Door.
Monitor security alerts and logs
Track diagnostic information including security alerts and logs that provide detailed reporting on detected threats with Azure Monitor.
“In our on-premises environment, each security layer was standalone, presented in several dashboards. In Azure, we wanted to focus not only on the available solutions, but also combining their functionalities into a single easy-to-deploy, easy-to-manage, highly secure environment.”
André Beerendonk, Team Manager for IT Operations, VECOZO
“Security requires a lot of investment and knowledge, and we need providers like Microsoft that we can trust so we can focus on the business. We use Azure DDoS Protection Standard and Azure Web Application Firewall on Azure Application Gateway to protect our business-critical workloads and data streams across our environment.”
Azure Web Application Firewall resources and documentation
Learning
Get started with Web Application Firewall
See how Azure Web Application Firewall protects Azure web applications from common attacks, and learn about its features, how it's deployed, and common use cases.
Azure Web Application Firewall is a cloud-native service that protects your web applications from bot attacks and common web vulnerabilities such as SQL injection and cross-site scripting.
Yes. Enable DDoS protection on Azure Virtual Network where Azure Application Gateway is deployed. This ensures that the Azure DDoS protection service also protects the application gateway virtual IP (VIP).