# Treat a custom DDoS threshold as a replacement for that protocol's autotuning

> Does a preview Azure DDoS custom threshold supplement or replace adaptive tuning?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:22+00:00
- Modified: 2026-09-10T02:08:04+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Does a preview Azure DDoS custom threshold supplement or replace adaptive tuning?

## Potentially affected

Review this only as a preview configuration for eligible Standard Load Balancer frontends. Confirm the current preview scope before planning a trial; do not apply this model to every Azure public endpoint or to outbound traffic.

## DSE recommendation

Approve the loss of adaptive behavior before selecting a static threshold.

## Article

## Source facts

In the Azure DDoS custom-policy preview, setting a protocol threshold disables automatic tuning for that protocol on the protected resource. Protocols without a custom rule keep adaptive tuning. Preview support is limited to Standard Load Balancer frontend IP configurations and inbound TCP, UDP and TCP SYN detection. Deleting the custom policy returns its associated frontends to adaptive tuning. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-custom-policy-portal).

## Applicability

Review this only as a preview configuration for eligible Standard Load Balancer frontends. Confirm the current preview scope before planning a trial; do not apply this model to every Azure public endpoint or to outbound traffic.

## DSE recommendation

Approve the loss of adaptive behavior before selecting a static threshold. Have the service owner describe normal traffic and expected legitimate spikes for each affected protocol. Identify which protocols should remain automatically tuned and document why an override is justified. Keep the original configuration and the approved return-to-adaptive decision available. Avoid copying a threshold from a different workload or treating a static value as an additional safety layer.

## Verification

Use a controlled, authorized nonproduction validation and compare the configured protocols, associated frontends and mitigation telemetry. Check that unmodified protocols retain the intended mode. Retain observed legitimate-traffic impact as well as detection results. If the trial requires a return to adaptive tuning, use a separately approved change and verify the resulting configuration rather than silently deleting the policy.

## Official references

[Microsoft Learn: Create a DDoS Protection custom policy in the Azure portal (preview)](https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-custom-policy-portal).

## Primary reference

- Name: Create a DDoS Protection custom policy in the Azure portal (preview) | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-custom-policy-portal
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Treat a custom DDoS threshold as a replacement for that protocol's autotuning,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-454-treat-a-custom-ddos-threshold-as-a-replacement-for-that-protocol-s-autotuning/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
