# Check Azure Firewall network matches before tightening an application rule

> A matching network rule terminates rule processing before an application rule is evaluated, regardless of numeric priorities across rule types.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-284-check-azure-firewall-network-matches-before-tightening-an-application-rule/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:12+00:00
- Modified: 2026-09-10T01:23:49+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

A matching network rule terminates rule processing before an application rule is evaluated, regardless of numeric priorities across rule types.

## Potentially affected

Azure Firewall configurations combining network and application rules.

## DSE recommendation

Trace the first applicable rule type and match before relying on an application-level restriction.

## Article

## Source facts

Azure Firewall processes network rules before application rules, and a network-rule match terminates that rule evaluation. Microsoft states that the rule-type order applies regardless of collection-group priority, collection priority or policy inheritance.

Consequently, changing an application collection’s numeric priority does not place it ahead of a matching network rule. This ordering does not remove other controls: configured threat-intelligence filtering runs before network and application rules, and IDPS can alert or block according to its mode. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/firewall/rule-processing).

## Applicability

Identify the actual traffic tuple and all applicable policies, including inherited rules. Keep the rule-engine match separate from the final outcome of other configured security controls.

## DSE recommendation

DSE recommends reviewing broad network allows whenever an application restriction appears ineffective. Determine whether the intended flow should be governed at the network layer or reach application evaluation. Propose the smallest reviewed rule change that implements that decision. Do not rely on a lower application priority number to repair a rule-type mismatch, and do not expand production access merely to reproduce the symptom.

## Verification

Use approved positive and negative requests and retain the matching rule and final traffic outcome for each. Include a flow that should remain permitted after the change. Correlate any additional security-engine logs rather than treating an Allow entry as the entire decision. Approve the revised policy only when the intended application restriction and necessary neighboring traffic both behave as planned.

## Official references

[Microsoft Learn: Azure Firewall rule processing logic](https://learn.microsoft.com/en-us/azure/firewall/rule-processing). Source retrieved September 9, 2026.

## Primary reference

- Name: Azure Firewall rule processing logic | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/firewall/rule-processing
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check Azure Firewall network matches before tightening an application rule,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-284-check-azure-firewall-network-matches-before-tightening-an-application-rule/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
