{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation/",
        "slug": "dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation/"
        },
        "title": "Separate Firewall Policy edit availability from continued firewall operation",
        "summary": "A policy-region outage can prevent changes while linked Azure Firewall instances continue operating.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:03+00:00",
        "modified_at": "2026-09-10T02:01:55+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 221,
        "potentially_affected": "Azure Firewall Policy objects linked to Azure Firewall instances within one Microsoft Entra tenant.",
        "dse_recommendation": "Track policy-edit capability and observed traffic enforcement as separate incident checks.",
        "primary_source": {
            "name": "Azure Firewall Manager policy overview | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/firewall-manager/policy-overview",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>An Azure Firewall Policy can be created in one region and associated globally with multiple firewall instances under the same Entra tenant. If its home region fails and has a paired region, the Resource Manager object metadata automatically fails over.</p>\n<p>During that failover, or while an unpaired home region remains failed, the policy object cannot be modified. Microsoft states that linked firewall instances continue operating. <a href=\"https://learn.microsoft.com/en-us/azure/firewall-manager/policy-overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the policy&#8217;s home region, paired-region context and associated firewalls. Distinguish the ability to submit an emergency rule change from the behavior of already configured traffic paths.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends maintaining separate incident observations for policy management and traffic enforcement. Record which proposed changes are blocked and which application paths are actually affected. Route emergency decisions through the incident owner rather than interpreting an editing failure as permission to bypass the firewall. Keep the last approved configuration available for comparison without assuming it establishes current application health.</p>\n<h2>Verification</h2>\n<p>During an incident or approved exercise, compare management-operation results with authorized permitted and denied traffic tests. Preserve their timestamps and scopes independently. After policy management recovers, reconcile queued changes with the current configuration before applying them. Do not claim that continued firewall operation guarantees every dependency or application remained available.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/firewall-manager/policy-overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Azure Firewall Manager policy overview</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nAn Azure Firewall Policy can be created in one region and associated globally with multiple firewall instances under the same Entra tenant. If its home region fails and has a paired region, the Resource Manager object metadata automatically fails over.\nDuring that failover, or while an unpaired home region remains failed, the policy object cannot be modified. Microsoft states that linked firewall instances continue operating. Microsoft Learn.\nApplicability\nIdentify the policy’s home region, paired-region context and associated firewalls. Distinguish the ability to submit an emergency rule change from the behavior of already configured traffic paths.\nDSE recommendation\nDSE recommends maintaining separate incident observations for policy management and traffic enforcement. Record which proposed changes are blocked and which application paths are actually affected. Route emergency decisions through the incident owner rather than interpreting an editing failure as permission to bypass the firewall. Keep the last approved configuration available for comparison without assuming it establishes current application health.\nVerification\nDuring an incident or approved exercise, compare management-operation results with authorized permitted and denied traffic tests. Preserve their timestamps and scopes independently. After policy management recovers, reconcile queued changes with the current configuration before applying them. Do not claim that continued firewall operation guarantees every dependency or application remained available.\nOfficial references\nMicrosoft Learn: Azure Firewall Manager policy overview. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nAn Azure Firewall Policy can be created in one region and associated globally with multiple firewall instances under the same Entra tenant. If its home region fails and has a paired region, the Resource Manager object metadata automatically fails over.\n\nDuring that failover, or while an unpaired home region remains failed, the policy object cannot be modified. Microsoft states that linked firewall instances continue operating. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/firewall-manager/policy-overview).\n\n## Applicability\n\nIdentify the policy’s home region, paired-region context and associated firewalls. Distinguish the ability to submit an emergency rule change from the behavior of already configured traffic paths.\n\n## DSE recommendation\n\nDSE recommends maintaining separate incident observations for policy management and traffic enforcement. Record which proposed changes are blocked and which application paths are actually affected. Route emergency decisions through the incident owner rather than interpreting an editing failure as permission to bypass the firewall. Keep the last approved configuration available for comparison without assuming it establishes current application health.\n\n## Verification\n\nDuring an incident or approved exercise, compare management-operation results with authorized permitted and denied traffic tests. Preserve their timestamps and scopes independently. After policy management recovers, reconcile queued changes with the current configuration before applying them. Do not claim that continued firewall operation guarantees every dependency or application remained available.\n\n## Official references\n\n[Microsoft Learn: Azure Firewall Manager policy overview](https://learn.microsoft.com/en-us/azure/firewall-manager/policy-overview). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate Firewall Policy edit availability from continued firewall operation",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation/",
                "headline": "Separate Firewall Policy edit availability from continued firewall operation",
                "description": "A policy-region outage can prevent changes while linked Azure Firewall instances continue operating.",
                "abstract": "A policy-region outage can prevent changes while linked Azure Firewall instances continue operating.",
                "articleBody": "Source facts\nAn Azure Firewall Policy can be created in one region and associated globally with multiple firewall instances under the same Entra tenant. If its home region fails and has a paired region, the Resource Manager object metadata automatically fails over.\nDuring that failover, or while an unpaired home region remains failed, the policy object cannot be modified. Microsoft states that linked firewall instances continue operating. Microsoft Learn.\nApplicability\nIdentify the policy’s home region, paired-region context and associated firewalls. Distinguish the ability to submit an emergency rule change from the behavior of already configured traffic paths.\nDSE recommendation\nDSE recommends maintaining separate incident observations for policy management and traffic enforcement. Record which proposed changes are blocked and which application paths are actually affected. Route emergency decisions through the incident owner rather than interpreting an editing failure as permission to bypass the firewall. Keep the last approved configuration available for comparison without assuming it establishes current application health.\nVerification\nDuring an incident or approved exercise, compare management-operation results with authorized permitted and denied traffic tests. Preserve their timestamps and scopes independently. After policy management recovers, reconcile queued changes with the current configuration before applying them. Do not claim that continued firewall operation guarantees every dependency or application remained available.\nOfficial references\nMicrosoft Learn: Azure Firewall Manager policy overview. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:26:03+00:00",
                "dateModified": "2026-09-10T02:01:55+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-353-separate-firewall-policy-edit-availability-from-continued-firewall-operation/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate Firewall Policy edit availability from continued firewall operation"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 221,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Azure Firewall Manager policy overview | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/firewall-manager/policy-overview"
                }
            }
        ]
    }
}