Description
Without an effective WAF policy association, Front Door cannot inspect or block requests using that policy. After association, also check whether the policy is enabled and which mode applies.
Potential impact
Malicious web requests may reach the origin application without being blocked by the WAF.
Remediation
Associate a policy with the required endpoints and review rules and exclusions. Detection mode logs matches; use Prevention when blocking is required and check the effect on legitimate requests.
Examples
These excerpts show policy association for an existing Front Door Classic deployment. Use Standard/Premium for new configurations; origins, routing, and policies are configured separately.
Before
hcl
resource "azurerm_frontdoor" "example" {
name = "example-frontdoor"
resource_group_name = azurerm_resource_group.example.name
backend_pool_settings {
enforce_backend_pools_certificate_name_check = true
}
frontend_endpoint {
name = "exampleFrontendEndpoint1"
host_name = "example-frontdoor.azurefd.net"
}
}
After
hcl
resource "azurerm_frontdoor" "example" {
name = "example-frontdoor"
resource_group_name = azurerm_resource_group.example.name
backend_pool_settings {
enforce_backend_pools_certificate_name_check = true
}
frontend_endpoint {
name = "exampleFrontendEndpoint1"
host_name = "example-frontdoor.azurefd.net"
web_application_firewall_policy_link_id = azurerm_frontdoor_firewall_policy.example.id
}
}