An Azure service that provides protection for web apps.
Hi @ Poorwa Kunwar,
Welcome to Microsoft Q&A Platform.
By excluding only the JSON arg name (RequestBodyJsonArgNames = session_id), you’ve turned off inspection of that one piece, but WAF still sees the Referer header and completes the compound match. Front Door’s managed-rule exclusions only let you skip individual match variables (JSON args, query args, header names/values, cookies, etc.), they don’t short-circuit a multi-match rule unless you exclude all of its parts—and, right now, “HeaderValue:referer” isn’t exposed in the portal dropdown.
Can exclusions work on compound rules?
You can only exclude each match variable that the rule uses. If you don’t (or can’t) exclude both the JSON arg and the header, the rule will still fire when the other part matches.
Can you exclude the Referer header condition?
Not via the portal today. Front Door WAF lets you exclude header names or header values in general, but it doesn’t list “HeaderValue:referer” under the FIX group exclusions.
Alternatively, you can create a Custom rule that will trigger before Managed rule set , You can create an Customer rule with match value. or If you want to use the Equals operator, you must specify the full URI, for example: https://xxxxxxxx/example/path instead of only the path /example/path.
If you prefer to match only the path, you should use the Contains operator in the custom rule instead of the Equals operator
If you do not want rule ID 943110 to be triggered, you can change its action to Log instead of contributing to the Anomaly Score.
Please
and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.