{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/",
        "slug": "dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/"
        },
        "title": "Preserve Front Door WAF overrides when changing a managed ruleset",
        "summary": "Compare managed-rule customizations before and after a ruleset change, especially when using the Azure portal.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:32+00:00",
        "modified_at": "2026-09-10T00:52:39+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 219,
        "potentially_affected": "Azure Front Door WAF policies changing managed ruleset versions.",
        "dse_recommendation": "Export and review rule states, actions, and exclusions before changing the managed ruleset version.",
        "primary_source": {
            "name": "Azure Web Application Firewall DRS rule groups and rules | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-drs",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Assigning a new managed ruleset through the Azure portal resets the existing managed-rule customizations to the new ruleset&#8217;s defaults. Microsoft specifically includes rule states, actions, and rule-level exclusions, while saying custom rules and policy settings are unaffected.</p>\n<p>Microsoft directs owners who need to retain overrides and exclusions to change the version through PowerShell, CLI, REST, or a template, then validate the changes before production deployment. <a href=\"https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-drs\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review the actual Front Door policy, current managed ruleset, proposed version, and chosen change tool. Keep managed-rule overrides distinct from separate custom rules so the impact comparison uses the correct configuration objects.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends a reviewed customization inventory with an owner and reason for each exception. Decide which overrides still belong in the new version instead of copying them without assessment. Preserve the previous policy and test plan, then choose the change method that matches the approved retention decision.</p>\n<h2>Verification</h2>\n<p>Apply the planned change to a test policy. Compare effective rule states, actions, and exclusions against the approved inventory, and exercise representative legitimate requests and approved security tests. Investigate unexpected blocking or newly broad exceptions before rollout. Record both the ruleset version and the resulting customization set in the release evidence.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-drs\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Azure Web Application Firewall DRS rule groups and rules</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nAssigning a new managed ruleset through the Azure portal resets the existing managed-rule customizations to the new ruleset’s defaults. Microsoft specifically includes rule states, actions, and rule-level exclusions, while saying custom rules and policy settings are unaffected.\nMicrosoft directs owners who need to retain overrides and exclusions to change the version through PowerShell, CLI, REST, or a template, then validate the changes before production deployment. Microsoft Learn.\nApplicability\nReview the actual Front Door policy, current managed ruleset, proposed version, and chosen change tool. Keep managed-rule overrides distinct from separate custom rules so the impact comparison uses the correct configuration objects.\nDSE recommendation\nDSE recommends a reviewed customization inventory with an owner and reason for each exception. Decide which overrides still belong in the new version instead of copying them without assessment. Preserve the previous policy and test plan, then choose the change method that matches the approved retention decision.\nVerification\nApply the planned change to a test policy. Compare effective rule states, actions, and exclusions against the approved inventory, and exercise representative legitimate requests and approved security tests. Investigate unexpected blocking or newly broad exceptions before rollout. Record both the ruleset version and the resulting customization set in the release evidence.\nOfficial references\nMicrosoft Learn: Azure Web Application Firewall DRS rule groups and rules. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nAssigning a new managed ruleset through the Azure portal resets the existing managed-rule customizations to the new ruleset’s defaults. Microsoft specifically includes rule states, actions, and rule-level exclusions, while saying custom rules and policy settings are unaffected.\n\nMicrosoft directs owners who need to retain overrides and exclusions to change the version through PowerShell, CLI, REST, or a template, then validate the changes before production deployment. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-drs).\n\n## Applicability\n\nReview the actual Front Door policy, current managed ruleset, proposed version, and chosen change tool. Keep managed-rule overrides distinct from separate custom rules so the impact comparison uses the correct configuration objects.\n\n## DSE recommendation\n\nDSE recommends a reviewed customization inventory with an owner and reason for each exception. Decide which overrides still belong in the new version instead of copying them without assessment. Preserve the previous policy and test plan, then choose the change method that matches the approved retention decision.\n\n## Verification\n\nApply the planned change to a test policy. Compare effective rule states, actions, and exclusions against the approved inventory, and exercise representative legitimate requests and approved security tests. Investigate unexpected blocking or newly broad exceptions before rollout. Record both the ruleset version and the resulting customization set in the release evidence.\n\n## Official references\n\n[Microsoft Learn: Azure Web Application Firewall DRS rule groups and rules](https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-drs). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Preserve Front Door WAF overrides when changing a managed ruleset",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/",
                "headline": "Preserve Front Door WAF overrides when changing a managed ruleset",
                "description": "Compare managed-rule customizations before and after a ruleset change, especially when using the Azure portal.",
                "abstract": "Compare managed-rule customizations before and after a ruleset change, especially when using the Azure portal.",
                "articleBody": "Source facts\nAssigning a new managed ruleset through the Azure portal resets the existing managed-rule customizations to the new ruleset’s defaults. Microsoft specifically includes rule states, actions, and rule-level exclusions, while saying custom rules and policy settings are unaffected.\nMicrosoft directs owners who need to retain overrides and exclusions to change the version through PowerShell, CLI, REST, or a template, then validate the changes before production deployment. Microsoft Learn.\nApplicability\nReview the actual Front Door policy, current managed ruleset, proposed version, and chosen change tool. Keep managed-rule overrides distinct from separate custom rules so the impact comparison uses the correct configuration objects.\nDSE recommendation\nDSE recommends a reviewed customization inventory with an owner and reason for each exception. Decide which overrides still belong in the new version instead of copying them without assessment. Preserve the previous policy and test plan, then choose the change method that matches the approved retention decision.\nVerification\nApply the planned change to a test policy. Compare effective rule states, actions, and exclusions against the approved inventory, and exercise representative legitimate requests and approved security tests. Investigate unexpected blocking or newly broad exceptions before rollout. Record both the ruleset version and the resulting customization set in the release evidence.\nOfficial references\nMicrosoft Learn: Azure Web Application Firewall DRS rule groups and rules. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:29:32+00:00",
                "dateModified": "2026-09-10T00:52:39+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Preserve Front Door WAF overrides when changing a managed ruleset"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 219,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Azure Web Application Firewall DRS rule groups and rules | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-drs"
                }
            }
        ]
    }
}