Azure WAF in Frontdoor premium: how to Exclude "matchVariableName":"MultipartParamValue:contentItem"

Owin Gruters - iO 46 Reputation points
2023-07-28T12:33:04.42+00:00

Hi,

When creating exclusions in a AFD Premium WAF policy, you have the choice out of 5 different Matchvariables: RequestHeaderNames, RequestCookieNames, QueryStringArgNames, RequestBodyPostArgNames, RequestBodyJsonArgNames (see https://learn.microsoft.com/en-us/azure/templates/microsoft.network/frontdoorwebapplicationfirewallpolicies?pivots=deployment-language-bicep#managedruleexclusion).

Now I have a (false) positive for rule Microsoft_DefaultRuleSet-2.1-MS-ThreatIntel-SQLI-99031004 with "matchVariableName":"MultipartParamValue:contentItem".

How do I exclude this one?

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
587 questions
{count} vote

1 answer

Sort by: Most helpful
  1. Owin Gruters - iO 46 Reputation points
    2023-09-30T13:01:33.2466667+00:00

    @Jean-Philippe Desloges-Bergeron latest communication I received from Microsoft yesterday Friday 29-9-2023:

    "update from the product team that they will roll out fix the log discrepancies on next week. I will keep you posted further updates on this once I hear anything from the product team. "

    0 comments No comments