What you need to know
Interpret Application Gateway WAF match events together with policy mode and the aggregate request score.
Potentially affected
Application Gateway WAF policies using managed-rule anomaly scoring.
DSE recommendation
Review contributing rule matches and the final action for the same request before deciding what the WAF did.
Source facts
In anomaly scoring, a rule match contributes to the request’s total. Microsoft’s example assigns five points to a Critical match and three to a Warning match. The match event itself is logged as Matched; it is not the final blocking decision.
At a total of five or more, a separate event records Blocked in Prevention mode or Detected in Detection mode. Microsoft identifies rule 949110 as an indication that the inbound anomaly score exceeded the threshold. Microsoft Learn.
Applicability
Identify the Application Gateway WAF policy, managed ruleset, mode, and the request under investigation. Keep individual signature matches distinct from the aggregate action and from the application’s actual response.
DSE recommendation
DSE recommends reviewing all related rule events before tuning a false positive. Record which matches contributed to the score and which final action occurred. Ask the application and security owners to assess the specific request; do not disable a broad threshold rule merely because its event is the last visible entry.
Verification
Use approved harmless test requests that exercise known rule behavior in a test policy. Compare contributing matches, aggregate action, policy mode, and observed request handling. Check that the reporting pipeline does not label every Matched event as a blocked request. Retain sanitized request context and the reviewed policy version for reproducibility.
Official references
Microsoft Learn: CRS and DRS rule groups and rules. Source retrieved September 9, 2026.
Review the official source
CRS and DRS rule groups and rules - Azure Web Application Firewall | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE