Recent Discussions
July 23rd Webinar Canceled: What's New in Azure Bastion
Hello everyone, Unfortunately, the webinar we had scheduled for July 23rd on What's New in Azure Bastion has been canceled for now. We apologize for any inconvenience and appreciate you all for being part of our community. All the best!27Views0likes0CommentsCanceled: Azure Firewall IDPS Detections and Sentinel Integration
Hello everyone, Unfortunately, the webinar we had scheduled for July 9th on Azure Firewall IDPS Detections and Sentinel Integration has been canceled for now. We apologize for any inconvenience and appreciate you all for being part of our community. All the best!198Views0likes1CommentLooking for a Microsoft FTE Co-Owner — New AVM Terraform Module: Network Security Perimeter
🔍 Looking for a Microsoft FTE Co-Owner — New AVM Terraform Module: Network Security Perimeter Hi EveryOne, I've just submitted a module proposal to the Azure Verified Modules (AVM) program for a Terraform resource module covering Azure Network Security Perimeter (Microsoft.Network/networkSecurityPerimeters). Module name: avm-res-network-networksecurityperimeter As a community contributor (non-FTE), I'm looking for a Microsoft FTE who is willing to take on the formal module owner role so we can move this forward together. I'm fully committed to doing the development work — building, testing, and maintaining the module to AVM specification — and I'm familiar with AVM standards, Terraform module structure, and the contribution flow. This module covers: - Network Security Perimeter resource lifecycle - Profile and access rule management (inbound/outbound) - PaaS resource associations - Diagnostic settings, locks, RBAC, and tags per AVM interface specs NSP is increasingly being mandated in enterprise Landing Zone deployments — especially in regulated industries — and there's currently no AVM Terraform representation for it. This is a great opportunity to fill a real gap in the ecosystem. If you're a Microsoft FTE interested in co-owning this module, please reply here or reach out directly. Happy to share the GitHub proposal link and discuss further. Thanks! #AzureVerifiedModules #Terraform #Azure #IaC #AzureLandingZones44Views0likes0CommentsHow to find Azure Firewall SNAT exhaustion on a compute unit?
I have some applications on my AKS cluster which frequently hits a application server. This application server URL is behind Akamai. When ever applications want to establish an SSL connection with the external URL, it has to go through Azure Firewall. I have occasional connection timeouts if a connection is not establish to Akamai servers in 1s. I saw that the SNAT Utilization is in the range of 10 percent to 30%. I know this graph is smoothened out across instances and can't see which Azure Firewall compute unit is getting overloaded if I have frequent access to one URL which goes through Akamai? Is there any way to find out the reason for these occasional connection timeouts with the external IPs(Akamai)? through logs or by any other means? I believe lack of the SNAT metrics by firewall compute unit is responsible for such tough debugging.105Views0likes1CommentShare Your Expertise: Help Shape Our Network Practitioner Community
Hello Azure network practitioners, We’re working on refining our understanding of network practitioner personas and building stronger community engagement strategies for networking practitioners. Your insights as an MVP are invaluable to this effort. Could you take a few minutes to complete this short survey? Your feedback will directly influence how we design future programs and resources for the community. 👉 https://forms.office.com/r/dfgXxNwQd9 Thank you for helping us make the Azure networking community even better! Best regards, Dan Product Marketing Manager, Identity & Network Access GrowthNew Blog | Monitoring Azure DDoS Protection Mitigation Triggers
By Saleem Bseeu Monitoring Azure DDoS Protection Mitigation Triggers In today’s digital landscape, Distributed Denial of Service (DDoS) attacks pose a significant threat to the availability and performance of online services. Azure DDoS Protection provides robust mechanisms to protect your applications and services against such attacks. In this blog post, we’ll explore how to monitor Azure DDoS Protection metrics for public IPs and demonstrate how to fully utilize the available metrics to monitor your public IPs for DDoS attacks. Understanding Public IP and Azure DDoS Protection Metrics Azure DDoS Protection offers a variety of metrics that provide insights into potential threats targeting your resources. Additionally, there are public IP platform metrics that we can leverage for monitoring traffic patterns. These metrics are accessible through Azure Monitor and can be used to set up alerts and automated responses. Read the full post here: Monitoring Azure DDoS Protection Mitigation Triggers370Views1like0CommentsNew Blog | Getting Started with Azure DDoS Protection REST API: A Step-by-Step Guide
By David Frazee REST API is a cornerstone in the management of resources on Azure, providing a streamlined and efficient approach for executing create, read, update, and delete (CRUD) operations. By leveraging HTTP methods such as GET, POST, PUT, and DELETE, REST API simplifies resource manipulation for administrators. Moreover, REST API’s support for various data formats, including JSON and XML, enhances its versatility, making it indispensable for automating workflows and facilitating continuous deployment and integration practices. Focusing on Azure DDoS Protection, we will delve into its REST API integration, which enables the configuration of plans, association of virtual networks and individual resources, and real-time protection status. This integration is crucial for maintaining robust security in the fast-paced environment of cloud deployments. It ensures that security protocols are not only enhanced but also keep pace with the rapid deployment cycles characteristic of modern cloud infrastructures. Read the full post here: Getting Started with Azure DDoS Protection REST API: A Step-by-Step Guide336Views1like0CommentsNew Blog | Utilizing Azure DDoS Protection Workbook for DDoS attack traffic Analysis
By Shabaz Shaik In today's digital age, the security of applications, servers, and networks is paramount. One of the most significant threats to this security is Distributed Denial of Service (DDoS) attacks. These attacks can cripple your infrastructure, leading to downtime, loss of revenue, and damage to your reputation. Therefore, it is crucial to implement robust protection mechanisms to safeguard your digital assets. Azure DDoS Protection offers a comprehensive solution to defend against these malicious attacks. It provides automatic attack detection and mitigation, ensuring that your applications and services remain available even during an attack. Azure DDoS Protection is seamlessly integrated with Azure's native services, making it an ideal choice for businesses already leveraging the Azure ecosystem. Some of the salient features of Azure DDoS Protection include Adaptive Tuning, Attack Analytics and Metrics, DDoS Rapid Response etc. By leveraging Azure DDoS Protection, businesses can ensure the resilience and availability of their digital infrastructure, providing peace of mind in an increasingly hostile cyber environment. Read the full post here: Utilizing Azure DDoS Protection Workbook for DDoS attack traffic Analysis354Views0likes0CommentsNew Blog | Azure WAF’s Bot Manager 1.1 and JavaScript Challenge: Navigating the Bot Threat Terrain
By Andrew Mathu Introduction Bots are a common presence on the internet, serving a range of functions from automating customer service to indexing pages for search engines. However, their capabilities can be exploited for malicious activities, such as launching botnet attacks that can compromise web applications and disrupt services. Businesses continuously face the delicate balancing act of allowing good bots to perform their functions while preventing bad bots from causing harm. To address these challenges, Azure Web Application Firewall (WAF) has new enhancements that provide advanced protection against such threats, ensuring the security and integrity of web applications. In this blog, we will explore Azure WAF Bot Manager 1.1 in Azure Front Door (AFD) and coming soon to Application Gateway WAF, as well as the WAF JavaScript Challenge which is available in both Application Gateway and Azure Front Door. These features offer comprehensive protection against malicious bots while ensuring that good bots can continue their work without interruption. Read the full post here: Azure WAF’s Bot Manager 1.1 and JavaScript Challenge: Navigating the Bot Threat Terrain387Views0likes0CommentsNew Blog | Configuration of Size Enforcement and Inspection Limits in Application Gateway WAF
By Andrew Mathu Introduction In the constantly changing world of cybersecurity, both flexibility and effective security are essential for safeguarding applications. To meet these needs, Microsoft Azure recently released, in General Availability, the independent configuration of size enforcement limits and inspection limits in Web Application Firewall (WAF) integrated in Application Gateway v2. This update also allows users to disable size limits for both request body and file uploads without affecting request body inspections. This enhancement will enable users to fine-tune these settings - providing the ability to balance their application security needs against request size requirements. In this blog, we explore this innovative new feature, covering its key aspects and capabilities. Read the full post here: Independent Configuration of Size Enforcement and Inspection Limits in Application Gateway WAF500Views1like0CommentsNew Blog | Private IP DNAT Support and Scenarios with Azure Firewall
By Gustavo Modena Introduction Azure Firewall is a cloud native security service to protect your workloads running in Azure. It is a stateful firewall as a service with built-in high availability and auto scale. Azure Firewall supports three rule types: DNAT, Network and Application rules. In this blog, we will talk about enhancements to the DNAT rules. Up until recently, DNAT rules only was only supported on the Firewall Public IP addresses, mostly used for incoming traffic. In this release, we have enhanced DNAT scenario to support port translation on Azure Private IP (VIP). This capability helps with connectivity between overlapped IP networks, which is a common scenario for enterprises when onboarding new partners to their network or merging with new acquisitions. DNAT on Private IP is also relevant for hybrid scenarios (connecting on-premises datacenters to Azure), where DNAT bridges the gap, enabling communication between private resources over non-routable IP addresses. Read the full post here: Private IP DNAT Support and Scenarios with Azure Firewall524Views0likes0CommentsLogic app search replace function usage example?
Can someone please give me an example function for search and replace? I'm using html in the sentinel 'add comments' operator and I'm seeing lots of \n characters. I want to remove them all so they don't write line feeds to the output and mess up my html markup. Thank you.Solved15KViews0likes7CommentsNew Blog | Getting Started with Azure WAF REST API for Azure Front Door: A Step-by-Step Guide
By David Frazee REST API plays a pivotal role in the management of resources on Azure, offering a standardized and methodical approach for handling operations such as create, read, update, and delete (CRUD). The use of HTTP methods, such as GET, POST, PUT, and DELETE, in REST API aligns with CRUD operations, making it intuitive for administrators to manipulate resources on Azure. Additionally, REST API supports a range of data formats, including JSON and XML, providing versatility in how data is consumed and transmitted. This is particularly valuable for automating workflows and enabling continuous deployment and integration practices. Focusing on Azure WAF, we'll examine its REST API integration for configuring rules, monitoring policies, and real-time threat response, vital for maintaining security in fast-paced cloud deployments. This seamless integration not only enhances security but also ensures that the management of security protocols keeps pace with the rapid deployment cycles inherent in modern cloud environments. Read the full post here: Getting Started with Azure WAF REST API for Azure Front Door: A Step-by-Step Guide296Views0likes0CommentsNew Blog | Azure Firewall and WAF integrations in Microsoft Copilot for Security
By Shabaz Shaik Azure Firewall and WAF are critical security services that many Microsoft Azure customers use to protect their network and applications from threats and attacks. Azure Firewall is a fully managed, cloud-native network security service that safeguards your Azure resources. It ensures high availability and scalability while filtering both inbound and outbound traffic, catching threats and only allowing legitimate traffic. Azure WAF is a cloud-native service that protects your web applications from common web-hacking techniques such as SQL injection and cross-site scripting. It offers centralized protection for web applications hosted behind Azure Application Gateway and Azure Front Door. The Azure Firewall integration in Copilot for Security enables analysts to perform detailed investigations of malicious traffic intercepted by the IDPS [Intrusion Detection and Prevention System] feature of their firewalls across their entire fleet. Analysts can use natural language queries in the Copilot for Security standalone experience for threat investigation. With the Azure WAF integration, security and IT teams can operate more efficiently, focusing on high-value tasks. Copilot summarizes data and generates in-depth contextual insights into the WAF threat landscape. Both integrations simplify complex tasks, allowing analysts to ask questions in natural language instead of writing complex KQL queries Read the full post here: Azure Firewall and WAF integrations in Microsoft Copilot for Security342Views0likes0CommentsNew Blog | Leveraging Azure DDoS protection with WAF rate limiting
By Saleem Bseeu Introduction In an increasingly interconnected world, the need for robust cybersecurity measures has never been more critical. As businesses and organizations migrate to the cloud, they must address not only the conventional threats but also more sophisticated ones like Distributed Denial of Service (DDoS) attacks. Azure, Microsoft's cloud computing platform, offers powerful tools to protect your applications and data. In this blog post, we will explore how to leverage Azure DDoS Protection in combination with Azure Web Application Firewall (WAF) rate limiting to enhance your security posture. Understanding DDoS Attacks Distributed Denial of Service attacks are a malicious attempt to disrupt the normal functioning of a network, service, or website by overwhelming it with a flood of internet traffic. These attacks can paralyze online services, causing severe downtime and financial losses. Azure DDoS Protection is a service designed to mitigate such attacks and ensure the availability of your applications hosted on Azure. Combining Azure DDoS Protection with WAF Rate Limiting While Azure DDoS Protection can mitigate many types of attacks, it's often beneficial to combine it with a Web Application Firewall for comprehensive security. Azure WAF provides protection at the application layer, inspecting HTTP/HTTPS traffic and identifying and blocking malicious requests. One of the key features of Azure WAF is rate limiting, which allows you to control the number of incoming requests from a single IP address or Geo location. By setting appropriate rate limiting rules, you can mitigate application-layer DDoS attacks. In this article, we will delve into DDoS protection logs, exploring how to harness this valuable data to configure rate limiting on the Application Gateway WAF. By doing so, we fortify our defenses at various layers, ensuring a holistic approach to DDoS protection. Read the full post here: Leveraging Azure DDoS protection with WAF rate limiting392Views0likes0CommentsNew Blog | Azure Firewall Protection Against Apache Struts Vulnerability - CVE-2023-50164
By Andrew Mathu Introduction Vulnerabilities and zero-day exploits continue to be a serious threat to systems worldwide. One such vulnerability is CVE-2023-50164, a critical issue in Apache Struts that can lead to critical security breaches if not properly mitigated. Protecting your systems from such vulnerabilities is paramount to prevent unauthorized access and data loss. Azure Firewall Premium provides a robust solution to safeguard your infrastructure against such threats. This blog post will explore the CVE-2023-50164 vulnerability and demonstrate how Azure Firewall Premium can effectively prevent this attack. Read the full post here: Azure Firewall Protection Against Apache Struts Vulnerability - CVE-2023-50164319Views0likes0CommentsNew Blog | Portal extension for Azure Firewall with DDoS protection
By Saleem Bseeu Introduction In the ever-evolving landscape of network security, Azure Firewall has emerged as a key player. As a managed, cloud-based network security service, it provides essential protection for your Azure Virtual Network resources. Cyber threats are increasingly sophisticated and frequent, the importance of robust security measures like Distributed Denial of Service (DDoS) protection cannot be overstated. DDoS attacks can cripple services, making them unavailable to users, which can have significant business implications. One of the motivations for integrating DDoS protection into the Azure Firewall creation flow is to simplify the process for users. Many users who deploy Azure Firewall also enable DDoS protection to protect their network resources. However, for those who may not be aware of the importance of DDoS protection or prefer a more straightforward setup process, the new creation flow makes it easier to enable this feature. By integrating DDoS protection into the Firewall creation process, users can activate this essential security measure with just a few clicks, enhancing the overall security of their network environment. The New Azure Firewall Flow Creation (Integrating DDoS Protection) The new Azure Firewall flow creation process represents a significant advancement in network security management. This process is designed to be user-friendly, providing a more streamlined experience for setting up and managing firewalls. These improvements not only enhance the user experience but also contribute to a more secure network environment. The new creation process is notable for its integration of DDoS protection, allowing users to activate this feature seamlessly during setup. This integration streamlines the process of enabling DDoS protection on Azure Firewall public IPs, making it easily accessible to users of all skill levels with just a few clicks. When customers activate DDoS Protection, they can enroll in DDoS IP Protection or DDoS Network Protection SKUs. These SKUs provide value-added features and capabilities, beyond the basic platform-level DDoS protection that safeguards Azure's infrastructure and services. DDoS attacks targeting your applications and resources are mitigated with a profile that is automatically adjusted to your expected traffic volume, along with attack alert notifications, logging and monitoring, cost protection, and DDoS Rapid Response (included with DDoS Network Protection). This ensures that, even in the event of a DDoS attack, services remain available and secure, which is vital in today's digital environment where service availability can have a direct impact on business operations. Note: This new flow creation is now available for preview. To access it, use the URL preview.portal.azure.com. Exploring the New Service Creation Flow Let's delve into the new service creation flow and learn how to navigate it. Start by accessing the Firewall service in your Azure portal and initiate the creation of a new Firewall. This initial step mirrors the process used in the past to create your Firewall. You'll need to select the resource, name, region, and availability zones that suit your needs. When it comes to Firewall SKU, you're presented with three options: Standard, Premium, and Basic. To gain a better understanding of which Firewall SKU aligns with your requirements, refer to Choose the right Azure Firewall SKU to meet your needs | Microsoft Learn Read the full post here: Portal extension for Azure Firewall with DDoS protection392Views0likes0CommentsNew Blog | Azure WAF Public Preview: JavaScript Challenge
By David Frazee Microsoft has recently released JavaScript challenge in public preview for Azure WAF on Application Gateway and Azure Front Door. Approximately 48% of internet traffic is generated by bots, with 30% attributed to malicious bots. These harmful bots are programmed to attack web and mobile applications for fraudulent and malevolent purposes. These bad bots are typically automated test scripts that scrape websites to manipulate SEO rankings or prices, launch denial-of-inventory attacks and commit other malicious activities. Considering the risks associated with internet-exposed web applications, it is necessary for Azure WAF to detect and mitigate the bad bots. The mitigation of these attacks is accomplished by the Azure WAF JavaScript challenge. The Azure WAF JavaScript (JS) challenge feature is a non-interactive, invisible web challenge used to distinguish legitimate users from bad bots. It is an invisible check issued to legitimate users and attackers as an intermediate page. Bad bots will fail the JS challenge but real users will not. Furthermore, JS challenges eliminate friction for real users since they don’t require any intervention from humans. Hence, Azure WAF JS challenge is an effective method to protect against bot attacks without introducing customer friction. Key Features The invisible challenge is presented when a user's request matches a specific rule, prompting the client's browser to compute the challenge without user interaction. Successful computation allows the user through, while failed attempts block malicious bots. The challenge is reissued if the user's IP address changes or if they access the page from a different domain, ensuring continuous protection. Read the full post here: Azure WAF Public Preview: JavaScript Challenge474Views0likes0CommentsNew Blog | Getting Started with Azure WAF REST API for Application Gateway: A Step-by-Step Guide
By David Frazee REST API plays a pivotal role in the management of resources on Azure, offering a standardized and methodical approach for handling operations such as create, read, update, and delete (CRUD). The use of HTTP methods, such as GET, POST, PUT, and DELETE, in REST API aligns with CRUD operations, making it intuitive for administrators to manipulate resources on Azure. Additionally, REST API supports a range of data formats, including JSON and XML, providing versatility in how data is consumed and transmitted. This is particularly valuable for automating workflows and enabling continuous deployment and integration practices. Focusing on Azure WAF, we'll examine its REST API integration for configuring rules, monitoring policies, and real-time threat response, vital for maintaining security in fast-paced cloud deployments. This seamless integration not only enhances security but also ensures that the management of security protocols keeps pace with the rapid deployment cycles inherent in modern cloud environments. Getting Started In the following examples, we’ll be using Postman to send our REST API requests to Azure Resource Manager to create, update, and delete the Azure WAF policy. There are other methods and tools to send REST APIs outside of Postman, such as PowerShell, Az CLI, Swagger, and more. The basics will be the same regardless of the tool or method used, just our interface will be different. To follow along, check out the prerequisites below to get started. Prerequisites: Link to download Postman: Postman API Platform | Sign Up for Free Link to blog that covers how to prepare your identities and Postman tool to send REST API commands: Azure REST APIs with Postman (2021) | Jon Gallant If you’re following along and have followed the prerequisites, you should now have your Postman Collection configured to something similar as below. Our first screenshot shows the Authorization tab in the Postman Collection. We’re going to use the Auth Type of Bearer Token and use the variable from our variables tab. Read the full post here: Getting Started with Azure WAF REST API for Application Gateway: A Step-by-Step Guide574Views0likes0Comments
Events
Recent Blogs
- 5 MIN READWritten in Collaboration with AvirupChat ShabazShaik Mohit_Kumar YuriDiogenes Introduction: As organizations move toward containerized workloads such as Azure Kubernetes Service (AKS), secur...Jul 09, 2026383Views0likes0Comments
- If you’ve worked with Azure Bastion’s Premium SKU, you’ve likely encountered one of its most powerful security features: graphical session recording. Capturing RDP and SSH sessions end to end strengt...Jun 11, 2026421Views1like0Comments