What you need to know
Application Gateway replaces the selector with an asterisk when an EqualsAny exclusion is created.
Potentially affected
Application Gateway v2 WAF policy exclusion reviews.
DSE recommendation
Review the exclusion operator, persisted selector and rule scope together before approving it.
Source facts
For an exclusion using EqualsAny, the Application Gateway backend converts any supplied selector to an asterisk. That operator selects all fields for the chosen match variable; a specific-looking value entered in the selector does not narrow it.
Exclusions can apply to a particular rule, rule group, ruleset or all rules. Microsoft recommends narrow exclusions and per-rule scope where possible. The match variable also determines whether a request key or its value is excluded from evaluation. Microsoft Learn.
Applicability
Identify the managed rule producing the false positive and the exact request attribute involved. Check the deployed policy, not only the intended selector in a change request.
DSE recommendation
DSE recommends choosing the smallest supported selector and rule scope that addresses the established false positive. Do not approve EqualsAny on the assumption that a descriptive selector limits it to one attribute. Have the application and security owners review neighboring fields that would otherwise lose evaluation. Preserve the reason and review trigger for the exception.
Verification
Inspect the saved exclusion operator and selector after an authorized change. Test the intended benign request and suitable neighboring cases in an approved environment to confirm the exception’s actual boundary. Review rule evaluation evidence rather than relying only on request success. Reconcile a persisted asterisk with the approved scope before enabling the exception more broadly.
Official references
Microsoft Learn: WAF Exclusion Lists in Azure Application Gateway. Source retrieved September 9, 2026.
Review the official source
WAF Exclusion Lists in Azure Application Gateway | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE