What you need to know
A matching network rule terminates rule processing before an application rule is evaluated, regardless of numeric priorities across rule types.
Potentially affected
Azure Firewall configurations combining network and application rules.
DSE recommendation
Trace the first applicable rule type and match before relying on an application-level restriction.
Source facts
Azure Firewall processes network rules before application rules, and a network-rule match terminates that rule evaluation. Microsoft states that the rule-type order applies regardless of collection-group priority, collection priority or policy inheritance.
Consequently, changing an application collection’s numeric priority does not place it ahead of a matching network rule. This ordering does not remove other controls: configured threat-intelligence filtering runs before network and application rules, and IDPS can alert or block according to its mode. Microsoft Learn.
Applicability
Identify the actual traffic tuple and all applicable policies, including inherited rules. Keep the rule-engine match separate from the final outcome of other configured security controls.
DSE recommendation
DSE recommends reviewing broad network allows whenever an application restriction appears ineffective. Determine whether the intended flow should be governed at the network layer or reach application evaluation. Propose the smallest reviewed rule change that implements that decision. Do not rely on a lower application priority number to repair a rule-type mismatch, and do not expand production access merely to reproduce the symptom.
Verification
Use approved positive and negative requests and retain the matching rule and final traffic outcome for each. Include a flow that should remain permitted after the change. Correlate any additional security-engine logs rather than treating an Allow entry as the entire decision. Approve the revised policy only when the intended application restriction and necessary neighboring traffic both behave as planned.
Official references
Microsoft Learn: Azure Firewall rule processing logic. Source retrieved September 9, 2026.
Review the official source
Azure Firewall rule processing logic | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE