Azure WAF is Microsoft's web application firewall, deployed either on Azure Front Door for global edge protection or on Application Gateway for regional, in-VNet protection. It ships managed rule sets based on the OWASP Core Rule Set plus Microsoft-authored rules, with custom rules, rate limiting, and geo-filtering on top.
If you represent Azure WAF, claiming is free and adds a Verified badge to this security profile. Start verification →
Its natural home is applications already running in Azure, where it integrates with the rest of the platform and is enabled as configuration rather than a separate vendor. A managed bot-protection rule set extends it beyond basic filtering.
Pricing is pay-as-you-go by policy and request volume. Like AWS WAF, it is the obvious choice when your app already lives on the matching cloud; for sites hosted elsewhere, an origin-agnostic edge WAF is more suitable.
Category context: Edge and cloud WAF platforms for larger sites and APIs, with managed rules, bot defence, and DDoS at global scale. Usually custom-priced.
Amazon's pay-as-you-go WAF that plugs into CloudFront, ALB, API Gateway, and AppSync.
Compare →The most widely used cloud WAF and CDN, filtering attacks at the DNS edge before they reach your origin.
Compare →The Signal Sciences engine on Fastly's edge, protecting web apps and APIs with low-friction, threshold-based blocking.
Compare →Azure WAF is Microsoft's web application firewall, available on Azure Front Door for global edge protection or on Application Gateway for regional, in-VNet protection. It uses managed OWASP-based and Microsoft rule sets plus custom rules, rate limiting, and geo-filtering, and integrates natively with Azure-hosted applications.
Azure WAF is billed pay-as-you-go based on the WAF policy and the volume of requests inspected, with the exact model depending on whether it runs on Front Door or Application Gateway. It is cost-effective for Azure-hosted apps and priced as part of the Azure platform.
Azure Front Door WAF protects at Microsoft's global edge, ideal for public, internet-facing sites needing CDN and global reach. Application Gateway WAF is regional and runs inside your virtual network, suited to internal or region-specific apps. Many architectures use Front Door for public traffic and Application Gateway for internal layers.
HostList is independent. This profile is editorial; HostList accepts no sponsorship, affiliate commission, or paid placement from Azure WAF or any security vendor.