Share via

WAF policy not exluding Header Content-type after exclusion

Owin Gruters - iO 46 Reputation points
2023-06-12T14:28:35.7566667+00:00

Hi,

In WAF policy for Azure Frontdoor Premium I get a false positive from a Header parameter Content-Type. User's image

I have made an exclusion for it, but keep getting the false positive. User's image

I have tried with exclusion of both RequestHeaderNames = "Content-Type" and also with RequestHeaderNames startsWith "Content", because maybe the dash had something to do with it. No success

Azure Front Door
Azure Front Door

An Azure service that provides a cloud content delivery network with threat protection.

{count} votes

1 answer

Sort by: Most helpful
  1. GitaraniSharma-MSFT 50,197 Reputation points Microsoft Employee Moderator
    2023-06-23T17:10:00.2766667+00:00

    Hello @Owin Gruters - iO ,

    I understand that you keep getting false positives from a Header parameter Content-Type in WAF policy for Azure Front Door Premium when accessing the Azure AD B2C signup flow, even after adding an exclusion for it.

    I discussed this issue with the Azure Front Door Product Group team, and they reproduced the issue on their end to investigate it further and found that it is a bug in AFD WAF, which will be fixed within the next few months (approx. ETA: before the end of September).

    For the time being, you can use a custom rule or disable the rule as a workaround. Apologies for the inconvenience.

    Kindly let us know if the above helps or you need further assistance on this issue.


    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.