An Azure service that provides a cloud content delivery network with threat protection.
Azure Front Door Premium WAF policy creation fails while Microsoft.Network/AllowFrontdoor remains Pending
I am configuring Azure Front Door Premium and cannot create a Web Application Firewall policy.
The Front Door Premium resources themselves are working correctly:
Front Door Premium profile is Active
Endpoint is provisioned successfully
Origin group and App Service origin are provisioned successfully
Private Link connection to App Service is Approved
Front Door routing is working
Custom domains and AFD-managed TLS certificates are validated and deployed
Requests through Front Door reach the application successfully
The required resource providers are registered:
Microsoft.Cdn = Registered
Microsoft.Network = Registered
However, this subscription feature remains:
Microsoft.Network/AllowFrontdoor = Pending
A minimal WAF policy creation attempt using Premium_AzureFrontDoor fails with:
(BadRequest) WebApplicationFirewallPolicy validation failed. More information "Policy ArmResourceId has incorrect formatting".
I have already:
registered Microsoft.Cdn
confirmed Microsoft.Network is registered
requested registration of Microsoft.Network/AllowFrontdoor
confirmed Azure Front Door Premium itself is functioning normally
confirmed there are no existing WAF policies in the resource group
reproduced the failure with a minimal standalone WAF policy
My question is:
For Azure Front Door Premium, what is the supported remediation when Microsoft.Network/AllowFrontdoor remains Pending and WAF policy creation fails with "Policy ArmResourceId has incorrect formatting"?
Does this feature require Microsoft-side subscription approval, or is there another supported configuration step that must be completed before creating a Premium Azure Front Door WAF policy?
I can provide subscription-specific IDs, timestamps, or correlation information privately if needed.