{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/",
        "slug": "dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/"
        },
        "title": "Treat a custom DDoS threshold as a replacement for that protocol's autotuning",
        "summary": "Does a preview Azure DDoS custom threshold supplement or replace adaptive tuning?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:22+00:00",
        "modified_at": "2026-09-10T02:08:04+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 243,
        "potentially_affected": "Review this only as a preview configuration for eligible Standard Load Balancer frontends. Confirm the current preview scope before planning a trial; do not apply this model to every Azure public endpoint or to outbound traffic.",
        "dse_recommendation": "Approve the loss of adaptive behavior before selecting a static threshold.",
        "primary_source": {
            "name": "Create a DDoS Protection custom policy in the Azure portal (preview) | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-custom-policy-portal",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>In the Azure DDoS custom-policy preview, setting a protocol threshold disables automatic tuning for that protocol on the protected resource. Protocols without a custom rule keep adaptive tuning. Preview support is limited to Standard Load Balancer frontend IP configurations and inbound TCP, UDP and TCP SYN detection. Deleting the custom policy returns its associated frontends to adaptive tuning. <a href=\"https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-custom-policy-portal\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review this only as a preview configuration for eligible Standard Load Balancer frontends. Confirm the current preview scope before planning a trial; do not apply this model to every Azure public endpoint or to outbound traffic.</p>\n<h2>DSE recommendation</h2>\n<p>Approve the loss of adaptive behavior before selecting a static threshold. Have the service owner describe normal traffic and expected legitimate spikes for each affected protocol. Identify which protocols should remain automatically tuned and document why an override is justified. Keep the original configuration and the approved return-to-adaptive decision available. Avoid copying a threshold from a different workload or treating a static value as an additional safety layer.</p>\n<h2>Verification</h2>\n<p>Use a controlled, authorized nonproduction validation and compare the configured protocols, associated frontends and mitigation telemetry. Check that unmodified protocols retain the intended mode. Retain observed legitimate-traffic impact as well as detection results. If the trial requires a return to adaptive tuning, use a separately approved change and verify the resulting configuration rather than silently deleting the policy.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-custom-policy-portal\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Create a DDoS Protection custom policy in the Azure portal (preview)</a>.</p>",
        "content_text": "Source facts\nIn the Azure DDoS custom-policy preview, setting a protocol threshold disables automatic tuning for that protocol on the protected resource. Protocols without a custom rule keep adaptive tuning. Preview support is limited to Standard Load Balancer frontend IP configurations and inbound TCP, UDP and TCP SYN detection. Deleting the custom policy returns its associated frontends to adaptive tuning. Microsoft Learn.\nApplicability\nReview this only as a preview configuration for eligible Standard Load Balancer frontends. Confirm the current preview scope before planning a trial; do not apply this model to every Azure public endpoint or to outbound traffic.\nDSE recommendation\nApprove the loss of adaptive behavior before selecting a static threshold. Have the service owner describe normal traffic and expected legitimate spikes for each affected protocol. Identify which protocols should remain automatically tuned and document why an override is justified. Keep the original configuration and the approved return-to-adaptive decision available. Avoid copying a threshold from a different workload or treating a static value as an additional safety layer.\nVerification\nUse a controlled, authorized nonproduction validation and compare the configured protocols, associated frontends and mitigation telemetry. Check that unmodified protocols retain the intended mode. Retain observed legitimate-traffic impact as well as detection results. If the trial requires a return to adaptive tuning, use a separately approved change and verify the resulting configuration rather than silently deleting the policy.\nOfficial references\nMicrosoft Learn: Create a DDoS Protection custom policy in the Azure portal (preview).",
        "content_markdown": "## Source facts\n\nIn the Azure DDoS custom-policy preview, setting a protocol threshold disables automatic tuning for that protocol on the protected resource. Protocols without a custom rule keep adaptive tuning. Preview support is limited to Standard Load Balancer frontend IP configurations and inbound TCP, UDP and TCP SYN detection. Deleting the custom policy returns its associated frontends to adaptive tuning. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-custom-policy-portal).\n\n## Applicability\n\nReview this only as a preview configuration for eligible Standard Load Balancer frontends. Confirm the current preview scope before planning a trial; do not apply this model to every Azure public endpoint or to outbound traffic.\n\n## DSE recommendation\n\nApprove the loss of adaptive behavior before selecting a static threshold. Have the service owner describe normal traffic and expected legitimate spikes for each affected protocol. Identify which protocols should remain automatically tuned and document why an override is justified. Keep the original configuration and the approved return-to-adaptive decision available. Avoid copying a threshold from a different workload or treating a static value as an additional safety layer.\n\n## Verification\n\nUse a controlled, authorized nonproduction validation and compare the configured protocols, associated frontends and mitigation telemetry. Check that unmodified protocols retain the intended mode. Retain observed legitimate-traffic impact as well as detection results. If the trial requires a return to adaptive tuning, use a separately approved change and verify the resulting configuration rather than silently deleting the policy.\n\n## Official references\n\n[Microsoft Learn: Create a DDoS Protection custom policy in the Azure portal (preview)](https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-custom-policy-portal)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Treat a custom DDoS threshold as a replacement for that protocol's autotuning",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/",
                "headline": "Treat a custom DDoS threshold as a replacement for that protocol's autotuning",
                "description": "Does a preview Azure DDoS custom threshold supplement or replace adaptive tuning?",
                "abstract": "Does a preview Azure DDoS custom threshold supplement or replace adaptive tuning?",
                "articleBody": "Source facts\nIn the Azure DDoS custom-policy preview, setting a protocol threshold disables automatic tuning for that protocol on the protected resource. Protocols without a custom rule keep adaptive tuning. Preview support is limited to Standard Load Balancer frontend IP configurations and inbound TCP, UDP and TCP SYN detection. Deleting the custom policy returns its associated frontends to adaptive tuning. Microsoft Learn.\nApplicability\nReview this only as a preview configuration for eligible Standard Load Balancer frontends. Confirm the current preview scope before planning a trial; do not apply this model to every Azure public endpoint or to outbound traffic.\nDSE recommendation\nApprove the loss of adaptive behavior before selecting a static threshold. Have the service owner describe normal traffic and expected legitimate spikes for each affected protocol. Identify which protocols should remain automatically tuned and document why an override is justified. Keep the original configuration and the approved return-to-adaptive decision available. Avoid copying a threshold from a different workload or treating a static value as an additional safety layer.\nVerification\nUse a controlled, authorized nonproduction validation and compare the configured protocols, associated frontends and mitigation telemetry. Check that unmodified protocols retain the intended mode. Retain observed legitimate-traffic impact as well as detection results. If the trial requires a return to adaptive tuning, use a separately approved change and verify the resulting configuration rather than silently deleting the policy.\nOfficial references\nMicrosoft Learn: Create a DDoS Protection custom policy in the Azure portal (preview).",
                "datePublished": "2026-09-10T00:24:22+00:00",
                "dateModified": "2026-09-10T02:08:04+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Treat a custom DDoS threshold as a replacement for that protocol's autotuning"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 243,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Create a DDoS Protection custom policy in the Azure portal (preview) | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-custom-policy-portal"
                }
            }
        ]
    }
}