Ensure that the Web Application Firewall (WAF) is enabled for your public facing web applications via Azure Application Gateway for additional inspection of incoming traffic.
This rule resolution is part of the Conformity Security & Compliance tool for Azure.
Azure Web Application Firewall (WAF) provides centralized protection of your web applications from common exploits and vulnerabilities such as SQL injections, Cross Site Scripting (XSS), and local and remote file executions. You can also restrict access to your web applications by countries, IP address ranges, and other HTTP(S) parameters via custom rules using the firewall service.
Audit
To determine if the Web Application Firewall (WAF) is enabled for your public facing web applications, perform the following actions:
Remediation / Resolution
To enable Web Application Firewall (WAF) support for your web applications via Azure Application Gateway, perform the following actions:
References
- Azure Official Documentation
- Microsoft Defender for Cloud documentation
- What is Microsoft Defender for Cloud?
- Azure Policy built-in policy definitions
- Manage security policies
- What is Azure Application Gateway?
- Azure Command Line Interface (CLI) Documentation
- az
- az account get-access-token
Unlock the Remediation Steps
Free 30-day Trial
Automatically audit your configurations with Conformity
and gain access to our cloud security platform.
You are auditing:
Monitor Web Application Firewall
Risk Level: Medium