Use Application Gateway WAF policy in prevention mode#
Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources.
Application Gateway WAF policies support two modes of operation, detection and prevention. By default, prevention is configured.
- Detection - monitors and logs all requests which match a WAF rule. In this mode, the WAF doesn't take action against incoming requests. To log requests, diagnostics on the Application Gateway instance must be configured.
- Protection - log and takes action against requests which match a WAF rule. The action to perform is configurable for each WAF rule.
Consider setting Application Gateway WAF policy to use protection mode.
- Best practices for endpoint security on Azure
- Securing PaaS deployments
- Web Application Firewall best practices