Azure update · August 24, 2026
Generally Available: Custom block response code and body for Application Gateway WAF
Announcing the General Availability of custom block response code and body for WAF integrated with Application Gateway
Azure WAF integrated with Application Gateway now supports customizable response status codes and bodies for blocked requests, enabling greater flexibility and control.
By default, when the WAF blocks a request due to a matched rule, it returns a 403 status code with a "The request is blocked" message. As with WAF with Azure Front Door, now customers can also define a custom response status code and message with Application Gateway when WAF blocks a request. This customization is a policy-level setting, ensuring that all blocked requests receive the same custom response status and message.
For further details, please reach out to the Azure WAF product team.
Brief published .