Azure Firewall Policy: Stuck in Updating State After Large Rule Changes — Troubleshooting and Resolution

LuisAbrajan-2096 0 Reputation points
2026-09-30T17:18:40.58+00:00

Problem description

I am facing an issue where my Azure Firewall Policy remains in the 'Updating' state after applying a large rule update. This causes subsequent Terraform deployments to fail with the error 'FirewallPolicyRuleCollectionGroupUpdateNotAllowed'. I am seeking guidance on whether the policy might be locked or stuck in a backend update, and how to resolve this situation.

Environment

Azure Firewall using a Firewall Policy in the East US 2 region, with policy and rule changes managed through Terraform.

What I've already tried

I have reviewed the case details and confirmed that a large firewall rule update was applied, after which the policy remained in 'Updating' state. I attempted Terraform deployments again, but they failed with the 'FirewallPolicyRuleCollectionGroupUpdateNotAllowed' error referencing a previous operation ID. I have not tried any other troubleshooting steps beyond this.

Current status

I am looking for assistance to determine if the policy is locked or stuck in backend, how to verify the status of the previous operation, and steps to resolve or reset the policy to allow further updates.

Azure Firewall
Azure Firewall

An Azure network security service that is used to protect Azure Virtual Network resources.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Allan Solomon Mejia 10,225 Reputation points
    2026-09-30T19:44:14.51+00:00

    Hi @LuisAbrajan-2096

    The error indicates that Azure is rejecting another rule-collection-group update while the parent Firewall Policy still has an unfinished update. Don't continue retrying Terraform until the policy leaves the Updating state.

    First, confirm the current provisioning state with Azure CLI:

    az network firewall policy show \
      --resource-group <resource-group> \
      --name <firewall-policy-name> \
      --query "{provisioningState:provisioningState,id:id}" \
      --output json
    

    You can also wait for the existing update to complete:

    az network firewall policy wait \
      --resource-group <resource-group> \
      --name <firewall-policy-name> \
      --updated \
      --interval 30 \
      --timeout 3600
    

    These are Azure CLI commands and can be run from Azure Cloud Shell or a local shell with Azure CLI installed. Both show and wait for the Azure Firewall Policy, including waiting until provisioningState becomes Succeeded.

    Next, open the policy or its resource group in the Azure portal and review the Activity log. Locate the operation ID or correlation ID from the original update and inspect its JSON details. Azure Activity Log records control-plane writes, their status, timestamps, correlation IDs, and response details.

    Also check Resource Health and Service Health for Azure Firewall or networking incidents in East US 2.

    Once the policy returns to Succeeded, run a fresh terraform plan before applying again. Ensure that another pipeline, portal operation, or deployment isn’t updating the same policy concurrently.

    If the state remains Updating after the original operation should reasonably have completed, open an Azure support request and provide the subscription ID, policy resource ID, region, timestamp, operation ID, and correlation ID. Microsoft’s Azure Firewall support guidance directs unresolved service-side problems to Azure Support.

    References:

    Azure Monitor Activity Log

    Find Azure Resource Manager error codes

    Monitor Azure Firewall

    Azure Service Health documentation

    Azure Firewall support and troubleshooting

    Create an Azure support request


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.