Skip to content

[Network] Expose WAF rule paranoiaLevel and rule set displayName #33879

Description

@Shaigoldbourt22

Preconditions

  • No need to upgrade Python SDK or the Python SDK is ready.

Related command

az network application-gateway waf-config list-rule-sets

az network application-gateway waf-config list-dynamic-rule-sets

Resource Provider

Microsoft.Network/applicationGateways

Description of Feature or Work Requested

Two new read-only fields in api-version 2026-01-01:

  1. paranoiaLevel on each managed rule (ApplicationGatewayFirewallRule). Values PL1 to PL4. It is the OWASP CRS paranoia level of the rule, where PL1 is baseline detection and PL4 is strictest. Set only for DRS and OWASP rule sets. Customers need it to understand why a rule fires and whether to disable it.

  2. displayName on the rule set (ApplicationGatewayFirewallRuleSetPropertiesFormat). For example "Default Ruleset 2.2 (Latest, Recommended)" or "Core Ruleset 3.0 (Deprecated)". Today the CLI only shows ruleSetType and ruleSetVersion, for example OWASP 3.0, so customers cannot tell which version is current and which is deprecated.

Both are output only. No new parameters and no behavior change.

Minimum API Version Required

2026-01-01

Swagger PR link / SDK link

https://github.com/Azure/azure-rest-api-specs-pr/pull/29807

Request Example

{
"listRuleSets": {
"command": "az network application-gateway waf-config list-rule-sets",
"operation": "ApplicationGatewayAvailableWafRuleSets",
"response": {
"value": [
{
"name": "Microsoft_DefaultRuleSet_2.1",
"properties": {
"ruleSetType": "Microsoft_DefaultRuleSet",
"ruleSetVersion": "2.1",
"displayName": "Default Ruleset 2.1",
"ruleGroups": [
{
"ruleGroupName": "RFI",
"description": "Remote file inclusion",
"rules": [
{
"ruleId": 931100,
"ruleIdString": "931100",
"description": "Possible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address",
"action": "AnomalyScoring",
"state": "Enabled",
"paranoiaLevel": "PL1"
}
]
}
]
}
}
]
}
},
"listDynamicRuleSets": {
"command": "az network application-gateway waf-config list-dynamic-rule-sets -l westus",
"operation": "ApplicationGatewayWafDynamicManifests_Get",
"response": {
"properties": {
"availableRuleSets": [
{
"ruleSetType": "Microsoft_DefaultRuleSet",
"ruleSetVersion": "2.2",
"displayName": "Default Ruleset 2.2 (Latest, Recommended)",
"status": "GA",
"tiers": [
"WAF_v2"
],
"ruleGroups": [
{
"ruleGroupName": "RFI",
"description": "Remote file inclusion",
"rules": [
{
"ruleId": 931100,
"ruleIdString": "931100",
"description": "Possible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address",
"action": "AnomalyScoring",
"state": "Disabled",
"paranoiaLevel": "PL1"
}
]
}
]
}
],
"defaultRuleSet": {
"ruleSetType": "Microsoft_DefaultRuleSet",
"ruleSetVersion": "2.2",
"_note": "displayName is defined in the spec here but the service does not return it yet"
}
}
}
}
}

Target Date

01.01.2027

PM Contact

yuvalpery

Engineer Contact

shgoldbourt

Additional context

No response

Activity

  1. yonzhan commented on Aug 12, 2026

    @yonzhan
    Collaborator

    Thank you for opening this issue, we will look into it.

  2. removed
    questionThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
    on Aug 12, 2026
  3. added this to the Backlog milestone on Aug 12, 2026
  4. Shaigoldbourt22 commented on Aug 25, 2026

    @Shaigoldbourt22
    Author

    The public spec has now merged.

    Azure/azure-rest-api-specs#45625 merged into release-microsoft-network-2026-01-01 on 24 August. It carries the same change as the private PR linked in the issue, so both fields are now in the public 2026-01-01 spec:

    • paranoiaLevel on ApplicationGatewayFirewallRule
    • displayName on the managed rule set

    Both are already live in production ARM. A GET at api-version 2026-01-01 returns them today.

    This should unblock Python SDK generation for these fields. Is anything else needed to move this out of Backlog?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions