Azure update · July 23, 2026

Public Preview: Azure DDoS Protection custom policy

Azure DDoS ProtectionIn previewAzure update

Azure DDoS Protection custom policy is now in public preview. This capability provides per-resource control over DDoS mitigation thresholds for protected Standard Load Balancer frontend IP configurations. 

Customers can configure fixed inbound detection thresholds for TCP, UDP, and TCP SYN traffic. Thresholds can be set from 50,000 to 2,000,000 packets per second, helping customers account for predictable or unusual traffic patterns, including planned launches, seasonal peaks, gaming events, and sustained high-volume workloads. 

When a custom threshold is configured for a protocol, Azure uses that threshold instead of adaptive auto-tuning for that protocol. Protocols without a custom threshold continue to use Azure DDoS Protection’s adaptive auto-tuning. 

During public preview, customers can create and manage Custom Policy through the Azure portal, Azure CLI, Azure Resource Manager templates, and the REST API. 

Custom policy currently supports inbound traffic for Standard Load Balancer frontend IP configurations. Regional availability is limited during the preview. 

Learn more:  

Brief published .