Azure DDoS Standard enable/disable on demand

AzureUser-9588 151 Reputation points
2020-11-19T04:54:45.123+00:00

From Microsoft documentation noticed that if Azure DDoS Standard was active only for a portion of the month, you would only receive a prorated bill for the hours used and data transfer overage incurred.

Is it possible for me to turn-on Azure DDoS Standard protection only when I detected that there was an attack on my resources and turn-off when its completed? Will Azure DDoS Standard would be able to protect underlying resources in this scenarios (kind of hypothetical)?

Azure DDos Protection
Azure DDos Protection
An Azure service that provides defense against distributed denial-of-service (DDoS) attacks.
68 questions
0 comments No comments
{count} votes

Accepted answer
  1. suvasara-MSFT 10,026 Reputation points
    2020-11-23T10:59:13.503+00:00

    @AzureUser-9588 , Apologies for the delay in response. If you have DDoS Protection Standard, make sure that it's enabled on the virtual network for constantly watching potential attacks on your infrastructure. DDoS Protection Standard applies three autotuned mitigation policies (TCP SYN, TCP, and UDP) for each public IP and these policy thresholds are autoconfigured via machine learning-based network traffic profiling. DDoS mitigation occurs for an IP address under attack only when the policy threshold is exceeded.

    Once you disable the DDOS on an IP, auto-tuned policy thresholds for that IP will be gone. So, it is not recommended.
    More on these policies can be refereed from this article Azure DDoS Protection features | Microsoft Learn

    ----------

    Please do not forget to "Accept the answer" wherever the information provided helps you to help others in the community.

    0 comments No comments

0 additional answers

Sort by: Most helpful