Skip to content

Enhance WAF tuning guidance with policy scope details - #128695

Open
Luke (Miskatonic-Electronic) wants to merge 1 commit into
MicrosoftDocs:mainfrom
Miskatonic-Electronic:patch-2
Open

Enhance WAF tuning guidance with policy scope details#128695
Luke (Miskatonic-Electronic) wants to merge 1 commit into
MicrosoftDocs:mainfrom
Miskatonic-Electronic:patch-2

Conversation

@Miskatonic-Electronic

Copy link
Copy Markdown
Contributor

Added section on understanding policy scope impact before tuning WAF rules and clarified the implications of disabling rules in the WAF policy.

Added section on understanding policy scope impact before tuning WAF rules and clarified the implications of disabling rules in the WAF policy.
@prmerger-automator

Copy link
Copy Markdown
Contributor

Luke (@Miskatonic-Electronic) : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change.

@prmerger-automator

Copy link
Copy Markdown
Contributor

Luke (@Miskatonic-Electronic) : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change.

@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit 771f18e:

✅ Validation status: passed

File Status Preview URL Details
articles/web-application-firewall/afds/waf-front-door-tuning.md ✅Succeeded

For more details, please refer to the build report.

@v-regandowner

Copy link
Copy Markdown
Contributor

mohitkusecurity

Can you review the proposed changes?

IMPORTANT: When the changes are ready for publication, adding a #sign-off comment is the best way to signal that the PR is ready for the review team to merge.

#label:"aq-pr-triaged"
@MicrosoftDocs/public-repo-pr-review-team

@prmerger-automator prmerger-automator Bot added the aq-pr-triaged tracking label for the PR review team label Aug 10, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Adds guidance to help readers understand how WAF policy association scope affects tuning decisions, and clarifies the impact/risk of disabling managed rules based on that scope.

Changes:

  • Added a new section explaining profile/domain/route association scope and precedence before tuning.
  • Updated the “disable rule” warning to reflect association scope (not always global to all hosts).
  • Added operational guidance for mixed-scope deployments and a “Related content” section.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines 459 to +461
> [!WARNING]
> When assigning a new managed ruleset to a WAF policy, all the previous customizations from the existing managed rulesets such as rule state, rule actions and rule level exclusions will be reset to the new managed ruleset's defaults. However, any custom rules and policy settings will remain unaffected during the new ruleset assignment.
>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants