# Preserve Front Door WAF overrides when changing a managed ruleset

> Compare managed-rule customizations before and after a ruleset change, especially when using the Azure portal.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:32+00:00
- Modified: 2026-09-10T00:52:39+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Compare managed-rule customizations before and after a ruleset change, especially when using the Azure portal.

## Potentially affected

Azure Front Door WAF policies changing managed ruleset versions.

## DSE recommendation

Export and review rule states, actions, and exclusions before changing the managed ruleset version.

## Article

## Source facts

Assigning a new managed ruleset through the Azure portal resets the existing managed-rule customizations to the new ruleset’s defaults. Microsoft specifically includes rule states, actions, and rule-level exclusions, while saying custom rules and policy settings are unaffected.

Microsoft directs owners who need to retain overrides and exclusions to change the version through PowerShell, CLI, REST, or a template, then validate the changes before production deployment. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-drs).

## Applicability

Review the actual Front Door policy, current managed ruleset, proposed version, and chosen change tool. Keep managed-rule overrides distinct from separate custom rules so the impact comparison uses the correct configuration objects.

## DSE recommendation

DSE recommends a reviewed customization inventory with an owner and reason for each exception. Decide which overrides still belong in the new version instead of copying them without assessment. Preserve the previous policy and test plan, then choose the change method that matches the approved retention decision.

## Verification

Apply the planned change to a test policy. Compare effective rule states, actions, and exclusions against the approved inventory, and exercise representative legitimate requests and approved security tests. Investigate unexpected blocking or newly broad exceptions before rollout. Record both the ruleset version and the resulting customization set in the release evidence.

## Official references

[Microsoft Learn: Azure Web Application Firewall DRS rule groups and rules](https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-drs). Source retrieved September 9, 2026.

## Primary reference

- Name: Azure Web Application Firewall DRS rule groups and rules | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-drs
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Preserve Front Door WAF overrides when changing a managed ruleset,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-144-preserve-front-door-waf-overrides-when-changing-a-managed-ruleset/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
