An Azure service that provides protection for web apps.
Hello Priya S
This looks like a WAF false-positive tuning issue.
The key point is that the missing-header rules are low severity:
-
920300Missing Accept → score 2 -
920320Missing User-Agent → score 2
Together they normally total 4, below the default blocking threshold of 5. A PHP rule such as 933180/933210 is Critical with score 5, so that is more likely to be the actual cause of the 403.
I would recommend:
- Use the WAF
transactionIdto review all matched rules for the blocked request. - If a specific field such as
citationtriggers933xxx, create a per-rule exclusion only for that request argument, rather than disabling the whole PHP rule group. - For legitimate requests missing
AcceptorUser-Agent, do not use a broad Allow rule. If required, disable/log only920300and920320, ideally in a separate per-URI WAF policy for the affected form path. - Avoid custom
Allow /forms/*rules because they can bypass managed-rule inspection.
Also narrow exclusions for false positives and supports per-URI WAF policies on Application Gateway WAF v2.
WAF false-positive troubleshooting