Check Azure Firewall network matches before tightening an application rule

A matching network rule terminates rule processing before an application rule is evaluated, regardless of numeric priorities across rule types.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

A matching network rule terminates rule processing before an application rule is evaluated, regardless of numeric priorities across rule types.

Potentially affected

Azure Firewall configurations combining network and application rules.

DSE recommendation

Trace the first applicable rule type and match before relying on an application-level restriction.

Source facts

Azure Firewall processes network rules before application rules, and a network-rule match terminates that rule evaluation. Microsoft states that the rule-type order applies regardless of collection-group priority, collection priority or policy inheritance.

Consequently, changing an application collection’s numeric priority does not place it ahead of a matching network rule. This ordering does not remove other controls: configured threat-intelligence filtering runs before network and application rules, and IDPS can alert or block according to its mode. Microsoft Learn.

Applicability

Identify the actual traffic tuple and all applicable policies, including inherited rules. Keep the rule-engine match separate from the final outcome of other configured security controls.

DSE recommendation

DSE recommends reviewing broad network allows whenever an application restriction appears ineffective. Determine whether the intended flow should be governed at the network layer or reach application evaluation. Propose the smallest reviewed rule change that implements that decision. Do not rely on a lower application priority number to repair a rule-type mismatch, and do not expand production access merely to reproduce the symptom.

Verification

Use approved positive and negative requests and retain the matching rule and final traffic outcome for each. Include a flow that should remain permitted after the change. Correlate any additional security-engine logs rather than treating an Allow entry as the entire decision. Approve the revised policy only when the intended application restriction and necessary neighboring traffic both behave as planned.

Official references

Microsoft Learn: Azure Firewall rule processing logic. Source retrieved September 9, 2026.

Primary reference

Review the official source

Azure Firewall rule processing logic | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE