Simplify and centralize network security management with Azure Firewall Manager

The substantive shift is not another security feature, but a control-plane consolidation: web application firewall policies and DDoS protection can now be administered alongside firewall policy in one place. For practitioners, that matters because network security in Azure is often fragmented across application gateways, front doors, virtual networks, and subscriptions. Centralized policy management reduces blind spots, makes posture review more realistic at scale, and turns security from isolated configuration tasks into an inventory and governance problem with clearer accountability.

Technically, the update extends Azure Firewall Manager from route and firewall oversight into Layer 7 and volumetric defense. WAF policy management now covers Azure Front Door and Application Gateway, including managed rulesets, exclusions, and disabled rule groups, while DDoS Protection Standard can be enabled on virtual networks without application changes. The practical value is consistency: administrators can import existing WAF policies, upgrade from older WAF configuration models, and compare protection across subscriptions and regions without jumping between services.

The limitation is that centralization does not eliminate architectural complexity; it mainly exposes it more coherently. Security teams still need to decide which workloads warrant WAF, DDoS Standard, or third-party controls, and the broader posture view is only as useful as the accuracy of the underlying deployments. The significance is operational: the platform is moving toward policy normalization and cross-tenant visibility, which helps mature teams find gaps sooner, but it should not be mistaken for automatic protection or complete coverage.


We are excited to share that Azure Web Application Firewall (WAF) policy and Azure DDoS Protection plan management in Microsoft Azure Firewall Manager is now generally available. With an increasing need to secure cloud deployments through a Zero Trust approach, the ability to manage network security policies and resources in one central place is a key security measure. Today, you can now centrally manage Original Postolicy-overview" target="_blank" rel="noopener" shape="rect">Azure Web Application Firewall (WAF) to provide Layer 7 application security to your application delivery platforms, Azure Front Door, and Azure Application Gateway, in your networks and across subscriptions. You can also configure DDoS Protection Standard for protecting your virtual networks from Layer 3 and Layer 4 attacks. Azure Firewall Manager is a central network security policy and route management service that allows administrators and organizations to protect their networks and cloud platforms at a scale, all in one central place. Azure Web Application Firewall is a cloud-native web application firewall (WAF) service that provides powerful protection for web apps from common hacking techniques such as SQL injection and security vulnerabilities such as cross-site scripting. Azure DDoS Protection Standard provides enhanced Distributed Denial-of-Service (DDoS) mitigation features to defend against DDoS attacks. It is automatically tuned to protect all public IP addresses in virtual networks. Protection is simple to enable on any new or existing virtual network and does not require any application or resource changes. By utilizing both WAF policy and DDoS protection in your network, this provides multi-layered protection across all your essential workloads and applications. WAF policy and DDoS Protection plan management are an addition to Azure Firewall management in Azure Firewall Manager.

Centrally protect your application delivery platforms using WAF policies

In Azure Firewall Manager, you can now manage and protect your Azure Front Door or Application Gateway deployments by associating WAF policies, at scale. This allows you to view all your key deployments in one central place, alongside Azure Firewall deployments and DDoS Protection plans. Associating a WAF policy to an Azure Front Door

Upgrade from WAF configuration to WAF policy

In addition, the platform supports administrators to upgrade from a WAF config to WAF policies for Application Gateways, by selecting the service andย Upgrade from WAF configuration. This allows for a more seamless process for migrating to WAF policies, which supports WAF policy settings, managed rulesets, exclusions, and disabled rule-groups. As a note, all WAF configurations that were previously created in Application Gateway can be done through WAF policy. Upgrading a WAF configuration to WAF policy

Manage DDoS Protection plans for your virtual networks

You can enable DDoS Protection Plan Standard on your virtual networks listed in Azure Firewall Manager, across subscriptions and regions. This allows you to see which virtual networks have Azure Firewall and/or DDoS protection in a single place.  Figure 3: Enabling DDoS Protection Standard on a virtual network in Azure Firewall Manager

View and create WAF policies and DDoS Protection Plans in Azure Firewall Manager

You can view andย createย WAF policies and DDoS Protection Plans from the Azure Firewall Manager experience, alongside Azure Firewall policies. In addition, you canย importย existing WAF policies to create a new WAF policy, so you do not need to start from scratch if you want to maintain similar settings. Figure 4: View of Web Application Firewall Policies in Azure Firewall Manager
Figure 5: View of DDoS Protection Plans in Azure Firewall Manager

Monitor your overall network security posture

Azure Firewall Manager provides monitoring of your overall network security posture. Here, you can easily see which virtual networks and virtual hubs are protected by Azure Firewall, a third-party security provider, or DDoS Protection Standard. This overview can help you identify and prioritize any security gaps that are in your Azure environment, across subscriptions or for the whole tenant. Figure 6: Monitoring page in Azure Firewall Manager
Coming soon, youโ€™ll also be able to view your Application Gateway and Azure Front Door monitors, for a full network security overview.

Learn more

To learn more about these features in Azure Firewall Manager, visit theย Manage Web Application Firewall policiesย tutorial,ย WAF on Application Gateway documentation, andย WAF on Azure Front Door documentation. For DDoS information, visit theย Configure Azure DDoS Protection Plan using Azure Firewall Manager tutorialย andย Azure DDoS Protection documentation. To learn more about Azure Firewall Manager, please visit theย Azure Firewall Manager home page.

Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.