An Azure service that provides protection for web apps.
An Allow rule for Canada does not block other countries; traffic that does not match simply continues to the next rule and may be allowed by the policy default.
Create one high-priority custom Match rule with:
- Match variable:
RemoteAddrfor the original client IP - Operator:
GeoMatch - Country:
CA - Negate condition: enabled
- Action:
Block
Also confirm the WAF policy is enabled, in Prevention mode, and associated with the correct Front Door domain. For strict Canada-only access, allow-list handling of ZZ/unknown addresses must be intentional; permitting ZZ also permits addresses Azure cannot geolocate.
Finally, check the WAF logs for this rule's name and block action. If requests reach the origin without a WAF log entry, they are bypassing Front Door, so restrict the origin to Front Door traffic only.