Treat a custom DDoS threshold as a replacement for that protocol's autotuning

Does a preview Azure DDoS custom threshold supplement or replace adaptive tuning?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Does a preview Azure DDoS custom threshold supplement or replace adaptive tuning?

Potentially affected

Review this only as a preview configuration for eligible Standard Load Balancer frontends. Confirm the current preview scope before planning a trial; do not apply this model to every Azure public endpoint or to outbound traffic.

DSE recommendation

Approve the loss of adaptive behavior before selecting a static threshold.

Source facts

In the Azure DDoS custom-policy preview, setting a protocol threshold disables automatic tuning for that protocol on the protected resource. Protocols without a custom rule keep adaptive tuning. Preview support is limited to Standard Load Balancer frontend IP configurations and inbound TCP, UDP and TCP SYN detection. Deleting the custom policy returns its associated frontends to adaptive tuning. Microsoft Learn.

Applicability

Review this only as a preview configuration for eligible Standard Load Balancer frontends. Confirm the current preview scope before planning a trial; do not apply this model to every Azure public endpoint or to outbound traffic.

DSE recommendation

Approve the loss of adaptive behavior before selecting a static threshold. Have the service owner describe normal traffic and expected legitimate spikes for each affected protocol. Identify which protocols should remain automatically tuned and document why an override is justified. Keep the original configuration and the approved return-to-adaptive decision available. Avoid copying a threshold from a different workload or treating a static value as an additional safety layer.

Verification

Use a controlled, authorized nonproduction validation and compare the configured protocols, associated frontends and mitigation telemetry. Check that unmodified protocols retain the intended mode. Retain observed legitimate-traffic impact as well as detection results. If the trial requires a return to adaptive tuning, use a separately approved change and verify the resulting configuration rather than silently deleting the policy.

Official references

Microsoft Learn: Create a DDoS Protection custom policy in the Azure portal (preview).

Primary reference

Review the official source

Create a DDoS Protection custom policy in the Azure portal (preview) | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE