# Do not use a selector label to narrow a WAF EqualsAny exclusion

> Application Gateway replaces the selector with an asterisk when an EqualsAny exclusion is created.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-561-do-not-use-a-selector-label-to-narrow-a-waf-equalsany-exclusion/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:35+00:00
- Modified: 2026-09-10T02:14:31+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Application Gateway replaces the selector with an asterisk when an EqualsAny exclusion is created.

## Potentially affected

Application Gateway v2 WAF policy exclusion reviews.

## DSE recommendation

Review the exclusion operator, persisted selector and rule scope together before approving it.

## Article

## Source facts

For an exclusion using EqualsAny, the Application Gateway backend converts any supplied selector to an asterisk. That operator selects all fields for the chosen match variable; a specific-looking value entered in the selector does not narrow it.

Exclusions can apply to a particular rule, rule group, ruleset or all rules. Microsoft recommends narrow exclusions and per-rule scope where possible. The match variable also determines whether a request key or its value is excluded from evaluation. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-waf-configuration).

## Applicability

Identify the managed rule producing the false positive and the exact request attribute involved. Check the deployed policy, not only the intended selector in a change request.

## DSE recommendation

DSE recommends choosing the smallest supported selector and rule scope that addresses the established false positive. Do not approve EqualsAny on the assumption that a descriptive selector limits it to one attribute. Have the application and security owners review neighboring fields that would otherwise lose evaluation. Preserve the reason and review trigger for the exception.

## Verification

Inspect the saved exclusion operator and selector after an authorized change. Test the intended benign request and suitable neighboring cases in an approved environment to confirm the exception’s actual boundary. Review rule evaluation evidence rather than relying only on request success. Reconcile a persisted asterisk with the approved scope before enabling the exception more broadly.

## Official references

[Microsoft Learn: WAF Exclusion Lists in Azure Application Gateway](https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-waf-configuration). Source retrieved September 9, 2026.

## Primary reference

- Name: WAF Exclusion Lists in Azure Application Gateway | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-waf-configuration
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not use a selector label to narrow a WAF EqualsAny exclusion,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-561-do-not-use-a-selector-label-to-narrow-a-waf-equalsany-exclusion/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
