Ensure Azure Application Gateway Web application firewall (WAF) is enabled
Description
WAF should be enabled to protect your web applications that are running behind the Application Gateway from common threats and vulnerabilities.
Remediation
Azure Console:
1. Navigate to the Application gateways.2. For each Application gateway:3. Select Web application firewall from the menu.4. Make sure that Firewall Status is enabled and that tier is WAF.Note: Choosing the WAF tier allows you to enable a web application firewall for enhanced security on your web applications. Changing from the WAF tier to the standard tier is not supported.