Distinguish a WAF rule match from the final anomaly-score action

Interpret Application Gateway WAF match events together with policy mode and the aggregate request score.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Interpret Application Gateway WAF match events together with policy mode and the aggregate request score.

Potentially affected

Application Gateway WAF policies using managed-rule anomaly scoring.

DSE recommendation

Review contributing rule matches and the final action for the same request before deciding what the WAF did.

Source facts

In anomaly scoring, a rule match contributes to the request’s total. Microsoft’s example assigns five points to a Critical match and three to a Warning match. The match event itself is logged as Matched; it is not the final blocking decision.

At a total of five or more, a separate event records Blocked in Prevention mode or Detected in Detection mode. Microsoft identifies rule 949110 as an indication that the inbound anomaly score exceeded the threshold. Microsoft Learn.

Applicability

Identify the Application Gateway WAF policy, managed ruleset, mode, and the request under investigation. Keep individual signature matches distinct from the aggregate action and from the application’s actual response.

DSE recommendation

DSE recommends reviewing all related rule events before tuning a false positive. Record which matches contributed to the score and which final action occurred. Ask the application and security owners to assess the specific request; do not disable a broad threshold rule merely because its event is the last visible entry.

Verification

Use approved harmless test requests that exercise known rule behavior in a test policy. Compare contributing matches, aggregate action, policy mode, and observed request handling. Check that the reporting pipeline does not label every Matched event as a blocked request. Retain sanitized request context and the reviewed policy version for reproducibility.

Official references

Microsoft Learn: CRS and DRS rule groups and rules. Source retrieved September 9, 2026.

Primary reference

Review the official source

CRS and DRS rule groups and rules - Azure Web Application Firewall | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE