Guidance for Azure Web Application Firewall — deployed on Azure Front Door (global, edge-tier) or Azure Application Gateway (regional, integrated with backend pools).

MITAuto-check passedSecurity

Install Azure Waf

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-waf -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills azure-waf --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-waf .claude/skills/azure-waf && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-waf
GitHub stars
175
Token cost
~2.2k tokens
SKILL.md length
900 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Azure Web Application Firewall — deployed on Azure Front Door (global, edge-tier) or Azure Application Gateway (regional, integrated with backend pools).

  • Works in 9 steps: Start in Detection (audit) mode. Always.… → Apply Microsoft's Default Rule Set… → Authentication-aware rules first. → …
  • L3/L4 DDoS (use azure-ddos-protection)
  • SKILL.md covers When to use, Pick the host, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Azure Waf is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Azure Web Application Firewall — deployed on Azure Front Door (global, edge-tier) or Azure Application Gateway (regional, integrated with backend pools). Covers WAF policy design with managed rule sets (Microsoft Default Rule Set, Bot Manager, OWASP CRS), custom rules (rate limit, geo-block, IP allow/deny), exclusion design (the long-tail tuning task that decides whether WAF stays in Prevention), JSON challenge / CAPTCHA, log analytics integration, false-positive triage workflow, integration with…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Rate limiting and Web application vulnerabilities. It works with Microsoft Azure and Microsoft Defender. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • L3/L4 DDoS (use azure-ddos-protection)
  • Azure Firewall design (use azure-firewall)
  • Non-HTTP workloads

Example prompts

  • “/azure-waf”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Start in Detection (audit) mode. Always. Two minimum weeks of production traffic
  2. Apply Microsoft's Default Rule Set (DRS). Current generation is preferred over
  3. Authentication-aware rules first.
  4. Tune exclusions iteratively. This is the core operational task and the reason
  5. Promote to Prevention rule by rule, not all at once. Start with high-confidence,
  6. Custom rules for business logic. Examples
  7. Logging & analytics. Send WAF logs to Log Analytics (and Sentinel). Build
  8. Operational ownership. WAF without a named app-team owner regresses. Monthly
  9. Pair with DDoS Protection on the front-door public IP / App Gateway public IP.

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Waf loads about 2.2k tokens when it runs. Until then it costs about 244 tokens; SKILL.md has 900 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~244
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 900 words, ~2,168 tokens.

Download SKILL.mdSave it as .claude/skills/azure-waf/SKILL.md (or your agent's skills folder).
name
azure-waf
description
Guidance for Azure Web Application Firewall — deployed on Azure Front Door (global, edge-tier) or Azure Application Gateway (regional, integrated with backend pools). Covers WAF policy design with managed rule sets (Microsoft Default Rule Set, Bot Manager, OWASP CRS), custom rules (rate limit, geo-block, IP allow/deny), exclusion design (the long-tail tuning task that decides whether WAF stays in Prevention), JSON challenge / CAPTCHA, log analytics integration, false-positive triage workflow, integration with Defender for Cloud and Sentinel, regional vs global trade-off, and migration from third-party WAF. WHEN: Azure WAF, Front Door WAF, Application Gateway WAF, OWASP CRS Azure, bot manager Azure, WAF custom rules, WAF rate limiting, WAF false positives, WAF exclusions, WAF prevention vs detection, JSON challenge WAF, geo-block WAF. DO NOT USE for L3/L4 DDoS (use azure-ddos-protection), Azure Firewall design (use azure-firewall), or non-HTTP workloads.
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Azure Web Application Firewall (WAF)

Azure WAF is an OWASP-aligned application-layer firewall available in two host services:

  • Azure Front Door (Premium / Standard) — global, anycast, edge-tier, ideal for internet-facing apps and APIs that benefit from edge presence and built-in caching.
  • Azure Application Gateway (WAF v2) — regional, integrated with backend pools, ideal for app-internal or VNet-bound workloads that already terminate on App Gateway.

When to use

Protecting public web applications and APIs from layer-7 attacks: SQLi, XSS, RCE patterns, automated scanners, credential stuffing, scraping, and bot abuse. Use this skill for host selection, policy authoring, exclusion tuning, and operational ownership.

Do not use this skill for layer 3/4 DDoS (azure-ddos-protection), east-west / non-HTTP traffic (azure-firewall), or non-HTTP protocols.

Pick the host

HostBest for
Front Door Premium WAFInternet apps/APIs needing global edge, advanced bot manager, JS/JSON challenges, private-link backends
Front Door Standard WAFCost-sensitive internet apps with managed Default Rule Set + custom rules
App Gateway WAF v2Regional apps already on App Gateway, VNet-internal apps, bring-your-own-cert/zonal needs

Rule of thumb: Internet-facing new build → Front Door Premium. Brownfield with existing App Gateway + sticky reasons → App Gateway WAF.

Approach

  1. Start in Detection (audit) mode. Always. Two minimum weeks of production traffic (more for seasonal apps) before flipping to Prevention.

  2. Apply Microsoft's Default Rule Set (DRS). Current generation is preferred over the older OWASP CRS for new deployments. Enable Bot Manager rule set on Premium for Front Door.

  3. Authentication-aware rules first.

    • Rate limit anonymous endpoints (login, search, signup) — typical 100/min/IP for login.
    • Geo-block countries you don't serve, but allowlist VPN concentrators or partner regions.
    • JSON / JS challenge on suspicious bot scores (Premium) — silently filters headless browsers.
  4. Tune exclusions iteratively. This is the core operational task and the reason most WAFs end up "in detection forever." Process:

    1. Pull Detection-mode hits from AzureDiagnostics / AGCWAFLogs.
    2. Group by rule ID + URI + parameter.
    3. Confirm legitimate traffic (e.g., a legit SOAP body with < characters, an API that legitimately includes SQL keywords).
    4. Add scoped exclusion for that rule on that URI/parameter — never disable the whole rule globally.
    5. Re-baseline weekly.
  5. Promote to Prevention rule by rule, not all at once. Start with high-confidence, low-FP rules (RCE patterns, command injection). Hold off on chatty rules (XSS, protocol violations) until exclusions are stable.

  6. Custom rules for business logic. Examples:

    • Block specific user agents in pen-test campaigns.
    • Allow a partner CIDR to bypass rate limits.
    • Require a specific header on internal APIs.
    • Geo-block all but expected countries for admin paths.
  7. Logging & analytics. Send WAF logs to Log Analytics (and Sentinel). Build:

    • Top blocked rules + top false-positive candidates (work queue).
    • Geo distribution of blocked traffic.
    • Rate-limit hits per endpoint.
    • Bot manager classification trends.
  8. Operational ownership. WAF without a named app-team owner regresses. Monthly:

    • Review new rule set updates from Microsoft (auto-applied by default; review log diffs).
    • Re-baseline exclusions after app deployments that change request shapes.
    • Validate Prevention coverage (no quietly-disabled rules).
  9. Pair with DDoS Protection on the front-door public IP / App Gateway public IP. WAF is L7; DDoS is L3/4. Both, always, for high-value public workloads.

Show full SKILL.md (387 more words)Show less

Guardrails

  • Do not deploy in Prevention on day one. False-positive outage in business hours.
  • Don't disable rules globally to chase a single FP. Use exclusions scoped to the URI / parameter / cookie / header that actually triggered.
  • Geo-block is a coarse tool. Travelers, VPN users, mobile-carrier IPs all roam. Prefer rate-limit + bot manager + auth posture over hard geo-deny for end-user paths.
  • Bot manager scores aren't binary. Use the score band model (low → JS challenge, medium → CAPTCHA, high → block). Hard-blocking middle bands hits real users.
  • Rate limits per IP behind shared NAT (carrier, corporate) hit too many real users. Pair with cookie/session + size the limit accordingly.
  • WAF in front of an API doesn't replace API auth/authz. It's defense-in-depth, not the primary control.
  • Multiple WAFs in series (third-party CDN WAF + Azure WAF) double-tune everything and frustrate engineers. Pick one as authoritative.
  • Default Rule Set updates can introduce new rules. Review changes quarterly so a rule update doesn't surprise-block production.

Common anti-patterns

  • "Prevention day-one" — outage; team disables WAF entirely; never re-enables. Now you have nothing.
  • "Disabled rule 942100 because one URI false-positives" — entire rule class off. Use exclusion.
  • "Rate limit = 1000/min globally" — useless on login endpoints, painful on static-asset endpoints. Per-endpoint tuning.
  • "Geo-block everywhere" — cuts customers, doesn't stop motivated attackers.
  • "Bot manager set to block all 'medium' scores" — blocks legitimate browser variants and partner integrations.
  • "WAF logs not in Sentinel" — invisible.
  • "Same WAF policy for all 30 apps" — exclusions become impossible. One policy per app or app family.
  • "Skipped Default Rule Set updates" — coverage stagnates while attacks evolve.

Example prompts

  • Migrate a public e-commerce app from a third-party WAF to Azure Front Door Premium WAF — design and cutover plan.
  • Build the exclusion-tuning workflow: log queries, weekly review, app-team approval.
  • Author custom rules: rate-limit /login 30/min/IP, JS challenge /api/search on bot-score medium, geo-block all but US/CA on /admin.
  • Promote a Detection-mode WAF policy to Prevention rule-by-rule with rollback triggers.
  • Sentinel workbook: top blocked rules, top FP candidates, geo distribution, bot manager trends.
  • Compare Front Door WAF vs App Gateway WAF for a regional banking app.
  • Design WAF + DDoS + private-link backend for a Foundry-hosted AI API.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/azure-waf of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Azure Waf next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Waf compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Waf this skillvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Implementing Cloud Waf Rulesmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Azure API Management Security Reviewthomast1906/github-copilot-agent-skills202—~3.1kAutomated safety check: PassMIT
API Security Checklistrevfactory/harness-1001.3k—~1.7kAutomated safety check: PassApache-2.0
Secure Code GuardianJeffallan/claude-skills12k—~1.8kAutomated safety check: PassMIT
API Security ReviewOWASP/secure-agent-playbook188—~744Automated safety check: PassCC-BY-4.0

Similar skills

  • Implementing Cloud Waf Rules

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Azure API Management Security Review

    thomast1906/github-copilot-agent-skills

    Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.

    202 GitHub stars~3.1k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Secure Code Guardian

    Jeffallan/claude-skills

    Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks.

    12k GitHub stars~1.8k tokensUpdated 7 days ago
    SecurityAuto-check passed
  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    188 GitHub stars~744 tokensUpdated 15 days ago
    SecurityAuto-check passed
  • Security Review

    affaan-m/ECC

    Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.

    277k GitHub starsUsed in 1 repo~3.2k tokens
    SecurityAuto-check: notes

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Azure Waf

What does Azure Waf do?

Guidance for Azure Web Application Firewall — deployed on Azure Front Door (global, edge-tier) or Azure Application Gateway (regional, integrated with backend pools). Azure Waf is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Azure Web Application Firewall — deployed on Azure Front Door (global, edge-tier) or Azure Application Gateway (regional, integrated with backend pools).

When should I use Azure Waf?

Azure Waf fits situations like: L3/L4 DDoS (use azure-ddos-protection); azure Firewall design (use azure-firewall); non-HTTP workloads.

How do I install Azure Waf in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-waf -a claude-code`. Or copy the skill folder (skills/azure-waf in vinayaklatthe/microsoft-security-skills) into .claude/skills/azure-waf in your project. Claude Code loads it when a task matches its description.

How do I install Azure Waf in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-waf -a codex`. Or copy the skill folder (skills/azure-waf in vinayaklatthe/microsoft-security-skills) into .agents/skills/azure-waf in your project. Codex loads it when a task matches its description.

Can I use Azure Waf in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-waf -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-waf, .gemini/skills/azure-waf, .github/skills/azure-waf and .opencode/skills/azure-waf in your project.

What does Azure Waf need to run?

SKILL.md names no scripts, command-line tools or credentials: Azure Waf is instructions for the agent only.

Does Azure Waf access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Azure Waf safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Waf use?

Azure Waf is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Waf use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Waf?

Skills that share tags, products or a category with Azure Waf: Implementing Cloud Waf Rules (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Azure API Management Security Review (thomast1906/github-copilot-agent-skills, 202 stars), API Security Checklist (revfactory/harness-100, 1.3k stars) and Secure Code Guardian (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Waf?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.