Review WAF policy associations for Azure Front Door

Associate required WAF policies with request-handling endpoints.

Description

Without an effective WAF policy association, Front Door cannot inspect or block requests using that policy. After association, also check whether the policy is enabled and which mode applies.

Potential impact

Malicious web requests may reach the origin application without being blocked by the WAF.

Remediation

Associate a policy with the required endpoints and review rules and exclusions. Detection mode logs matches; use Prevention when blocking is required and check the effect on legitimate requests.

Examples

These excerpts show policy association for an existing Front Door Classic deployment. Use Standard/Premium for new configurations; origins, routing, and policies are configured separately.

Before

hcl
resource "azurerm_frontdoor" "example" {
  name                                         = "example-frontdoor"
  resource_group_name                          = azurerm_resource_group.example.name
  backend_pool_settings {
    enforce_backend_pools_certificate_name_check = true
  }

  frontend_endpoint {
    name      = "exampleFrontendEndpoint1"
    host_name = "example-frontdoor.azurefd.net"
  }
}

After

hcl
resource "azurerm_frontdoor" "example" {
  name                                         = "example-frontdoor"
  resource_group_name                          = azurerm_resource_group.example.name
  backend_pool_settings {
    enforce_backend_pools_certificate_name_check = true
  }

  frontend_endpoint {
    name                                   = "exampleFrontendEndpoint1"
    host_name                              = "example-frontdoor.azurefd.net"
    web_application_firewall_policy_link_id = azurerm_frontdoor_firewall_policy.example.id
  }
}

References