WAF Rule Exclusion Not Working for FIX Rule Group Rule 943110 in Microsoft_DefaultRuleSet_2.1

Poorwa Kunwar 20 Reputation points
2026-04-07T17:10:36.0633333+00:00

Hi Community,

I have configured a rule exclusion on our Azure Front Door WAF policy but the rule continues to fire despite the exclusion being in place for several hours. Looking for help understanding if this is a known limitation or a bug.

Setup:

  • Azure Front Door WAF
  • Rule Set: Microsoft_DefaultRuleSet_2.1
  • Rule Group: FIX
  • Rule: 943110 - Possible Session Fixation Attack: SessionID Parameter Name with Off-Domain Referer

Exclusion Configured:

  • Scope: Entire FIX rule group
  • Match variable: RequestBodyJsonArgNames
  • Operator: Equals
  • Selector: session_id

WAF Log Still Showing:

ruleName_s: Microsoft_DefaultRuleSet-2.1-FIX-943110
details_msg_s: Possible Session Fixation Attack: SessionID Parameter Name with Off-Domain Referer
details_matches_s: [{"matchVariableName":"JsonKey","matchVariableValue":"session_id"},
                    {"matchVariableName":"HeaderValue:referer","matchVariableValue":"[REDACTED]"}]
action_s: AnomalyScoring

Context:

  • Frontend and API are on different subdomains of the same domain
  • Rule 943110 appears to be a compound rule matching on both JsonKey = session_id AND HeaderValue:referer
  • The exclusion on RequestBodyJsonArgNames = session_id should prevent the rule from firing but isn't
  • The exclusion has been in place for several hours so propagation delay is not the issue

Questions:

  1. Can exclusions work on compound rules that match on both JSON body AND header values simultaneously?
  2. Is there a way to exclude the HeaderValue:referer condition? It doesn't appear as an option in the portal dropdown
  3. Is this a known limitation of the FIX rule group exclusions?

Any help appreciated!

Azure Web Application Firewall

Answer accepted by question author
Vallepu Venkateswarlu 10,595 Reputation points Microsoft External Staff Moderator
2026-04-07T17:38:07.8266667+00:00

Hi @ Poorwa Kunwar,

Welcome to Microsoft Q&A Platform.

By excluding only the JSON arg name (RequestBodyJsonArgNames = session_id), you’ve turned off inspection of that one piece, but WAF still sees the Referer header and completes the compound match. Front Door’s managed-rule exclusions only let you skip individual match variables (JSON args, query args, header names/values, cookies, etc.), they don’t short-circuit a multi-match rule unless you exclude all of its parts—and, right now, “HeaderValue:referer” isn’t exposed in the portal dropdown.

Can exclusions work on compound rules?

You can only exclude each match variable that the rule uses. If you don’t (or can’t) exclude both the JSON arg and the header, the rule will still fire when the other part matches.

Can you exclude the Referer header condition?

Not via the portal today. Front Door WAF lets you exclude header names or header values in general, but it doesn’t list “HeaderValue:referer” under the FIX group exclusions.

Alternatively, you can create a Custom rule that will trigger before Managed rule set , You can create an Customer rule with match value. or If you want to use the Equals operator, you must specify the full URI, for example: https://xxxxxxxx/example/path instead of only the path /example/path.

If you prefer to match only the path, you should use the Contains operator in the custom rule instead of the Equals operator

If you do not want rule ID 943110 to be triggered, you can change its action to Log instead of contributing to the Anomaly Score. User's image

Please210246-screenshot-2021-12-10-121802.pngand “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.