Azure DDoS Protection
Protect your Azure resources from distributed denial-of-service (DDoS) attacks.
Always-on monitoring and automatic DDoS network attack mitigation
Help protect your apps and resources with a profile automatically tuned to your expected traffic volume. Defend against even the most sophisticated attacks with an Azure global network that gives you dedicated monitoring, logging, telemetry, and alerts. Choose from options, Network Protection and IP Protection, that meet the protection and cost needs of all organizations - from enterprises to small and medium businesses.
Adaptive threat intelligence automatically detects and mitigates even the most complex DDoS attacks
Massive DDoS mitigation capacity scrubs traffic at the network edge before it impacts applications
Full visibility into DDoS attacks with actionable insights for quick response
Easy-to-deploy, multilayered DDoS protection immediately helps safeguard all resources on virtual networks upon enablement
Minimize application downtime and latency during attacks
Monitor your app traffic patterns all day, every day with adaptive tuning that compares actual traffic against thresholds defined in your DDoS policy. Mitigate DDoS attacks instantaneously without impacting the availability or performance of highly latency-sensitive applications.
Set up multilayer protection within minutes
Defend against a comprehensive set of network layer (layer 3/4) attacks, and from common application layer (layer 7) attacks. Deployed with Azure Application Gateway web application firewall (WAF), protection is easy to enable on any new or existing virtual network, and requires no user configuration or application or resource changes. Inline DDoS protection is offered through partner network virtual appliances deployed with Azure Gateway Load Balancer.
Interoperate seamlessly with other Azure services
Provide comprehensive protection and performance with Azure Monitor for alerting, metrics, and insights, and Microsoft Defender for Cloud for security posture management. Use your logs with Microsoft Sentinel and other security information and event management solutions.
Protect your apps with the security Microsoft uses
Reduce risk and focus on keeping your business running efficiently with the same security solution Microsoft uses to help safeguard critical services.
Eliminate critical business impact with rapid response
Engage the DDoS Protection rapid response team for help during an active attack. Get help with investigation, custom mitigation, analysis, and, if necessary, fast-track your incident to Microsoft support.
Avoid unforeseen costs of DDoS attacks
Help protect against the costs of DDoS-related usage spikes, such as app-scaling charges and bandwidth surges, with DDoS Protection. You won't be charged for attack traffic, and you'll receive service credit for resource costs incurred from a documented DDoS attack.
Comprehensive security and compliance, built in
Microsoft invests more than $1 billion annually on cybersecurity research and development.
We employ more than 3,500 security experts who are dedicated to data security and privacy.
Azure DDoS Protection pricing
Help protect your Azure resources from DDoS attacks with always-on monitoring and automatic network attack mitigation. There are no upfront commitments, no termination fees, and your total cost scales with your cloud deployment.
Get started with an Azure free account
After your credit, move to pay as you go to keep building with the same free services. Pay only if you use more than your free monthly amounts.
Trusted by companies of all sizes
Frequently asked questions about Azure DDoS Protection
Distributed denial of service (DDoS) is a type of attack where an attacker sends more requests to an application than the application is capable of handling. This depletes resources, affecting the application's availability and its ability to service customers. Over the past few years, the industry has seen a sharp increase in attacks, which are becoming more sophisticated and larger in magnitude. DDoS attacks can target any endpoint that's publicly reachable through the internet.
DDoS Network Protection, combined with application design best practices, provides enhanced DDoS mitigation features to defend against DDoS attacks. It's automatically tuned to help protect your specific Azure resources in a virtual network. Protection is easy to enable on any new or existing virtual network, and requires no application or resource changes. It has several advantages over the default infrastructure-level DDoS protection, including logging, alerting, and telemetry. See DDoS Network Protection overview for more details.
DDoS Protection is zone-resilient by default, and managed by the service itself. No customer configuration is necessary to enable zone resiliency.
Use DDoS Protection service in combination with a web application firewall (WAF) for protection both at the network layer (layer 3 and 4, offered by DDoS Network Protection) and at the application layer (layer 7, offered by a WAF). Offerings include Application Gateway WAF and other web application firewall apps available in Azure Marketplace.
Public IPs in a Azure Resource Manager-based Azure Virtual Network are currently the only type of protected resource. PaaS services (multitenant) are not supported. See DDoS Network Protection reference architectures for details.