Microsoft-Azure-Application-Gateway/V2

Priya S 0 Reputation points
2026-09-24T00:30:10.35+00:00

We are seeing intermittent 403 Forbidden errors on all forms hosted on our Azure App Service behind Application Gateway WAF. Firewall logs show false positives, including Missing User-Agent Header, Missing Accept Header (REQUEST‑920‑PROTOCOL‑ENFORCEMENT), and PHP Injection Attack: Variable Function Call Found (rule 933). These blocks occur even for legitimate public form submissions. Request headers are controlled by user browsers, and legal citations like “32042(d)(2)” are misidentified as PHP function calls. We need guidance from WAF engineering on safe, narrow tuning options to prevent blocking valid traffic without weakening overall security.

Azure Web Application Firewall
0 comments No comments

1 answer

Sort by: Most helpful
  1. Andriy Bilous 12,276 Reputation points MVP
    2026-09-24T05:00:24.7066667+00:00

    Hello Priya S

    This looks like a WAF false-positive tuning issue.

    The key point is that the missing-header rules are low severity:

    • 920300 Missing Accept → score 2
    • 920320 Missing User-Agent → score 2

    Together they normally total 4, below the default blocking threshold of 5. A PHP rule such as 933180/933210 is Critical with score 5, so that is more likely to be the actual cause of the 403.

    I would recommend:

    • Use the WAF transactionId to review all matched rules for the blocked request.
    • If a specific field such as citation triggers 933xxx, create a per-rule exclusion only for that request argument, rather than disabling the whole PHP rule group.
    • For legitimate requests missing Accept or User-Agent, do not use a broad Allow rule. If required, disable/log only 920300 and 920320, ideally in a separate per-URI WAF policy for the affected form path.
    • Avoid custom Allow /forms/* rules because they can bypass managed-rule inspection.

    Also narrow exclusions for false positives and supports per-URI WAF policies on Application Gateway WAF v2.

    WAF false-positive troubleshooting

    Managed rule IDs and anomaly scores

    WAF policy / per-URI policy

    WAF exclusions

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.