A cloud-native web application firewall (WAF) service that provides powerful protection for web apps
Azure WAF is a cloud-native service that protects web applications and API from common web-exploit techniques such as SQL injection and security vulnerabilities like cross-site scripting. Azure WAF is a PCI-compliant service that can detect and block malicious bot and DDoS at the edge. Azure WAF can be deployed in minutes with pre-configured managed rule sets that extend protection beyond OWASP top 10 security risks using Microsoft threat intelligence. With Azure WAF, you only pay for what you use.
Explore pricing options
Apply filters to customize pricing options to your needs.
Prices are estimates only and are not intended as actual price quotes. Actual pricing may vary depending on the type of agreement entered with Microsoft, date of purchase, and the currency exchange rate. Prices are calculated based on US dollars and converted using London closing spot rates that are captured in the two business days prior to the last business day of the previous month end. If the two business days prior to the end of the month fall on a bank holiday in major markets, the rate setting day is generally the day immediately preceding the two business days. This rate applies to all transactions during the upcoming month. Sign in to the Azure pricing calculator to see pricing based on your current program/offer with Microsoft. Contact an Azure sales specialist for more information on pricing or to request a price quote. See frequently asked questions about Azure pricing.
US government entities are eligible to purchase Azure Government services from a licensing solution provider with no upfront financial commitment, or directly through a pay-as-you-go online subscription.
Important—The price in R$ is merely a reference; this is an international transaction and the final price is subject to exchange rates and the inclusion of IOF taxes. An eNF will not be issued.
US government entities are eligible to purchase Azure Government services from a licensing solution provider with no upfront financial commitment, or directly through a pay-as-you-go online subscription.
Important—The price in R$ is merely a reference; this is an international transaction and the final price is subject to exchange rates and the inclusion of IOF taxes. An eNF will not be issued.
Azure WAF with Application Gateway v2
Azure Application Gateway WAF v2 SKU offer support for autoscaling, zone redundancy, and Static VIP. These gateways also offer enhanced performance, better provisioning, and configuration update time, header rewrites, and WAF custom rules. Please refer to Azure Application Gateway pricing page for details on additional non-WAF SKUs and documentation for more product details. See FAQ section below for pricing and billing information.
| Web Application Firewall Application Gateway | |
|---|---|
| Fixed | $- per gateway-hour | 
| Capacity Unit1 | $- per capacity unit-hour | 
Data transfers
Inbound data transfers i.e. data going into Azure data centers is free. Outbound data transfers i.e. data going out of Azure data centers from application gateway are charged at standard data transfer rates.
Azure WAF with Application Gateway v1
We charge for the application gateways based on the amount of time that the gateway is provisioned and available, as well as the amount of data processed by the application gateways. Please refer to Azure Application Gateway pricing page for details on additional non-WAF SKUs.
| Application Gateway Type | Web Application Firewall Application Gateway | 
|---|---|
| Small | Not available | 
| Medium | $- per gateway-hour (~$-/month) | 
| Large | $- per gateway-hour (~$-/month) | 
For technical specifications and limitations regarding the different application gateways, please refer to this overview.
Data processing
Data processing charge is based on the amount of data processed by the application gateways.
| Data Processing | Price | 
|---|---|
| Small | |
| Unlimited | $- per GB/month | 
| Medium | |
| First 10 TB/month | Included | 
| Unlimited | $- per GB/month | 
| Over 10 TB/month | $- per GB/month | 
| Large | |
| First 40 TB/month | Included | 
| Unlimited | $- per GB/month | 
| Over 40 TB/month | $- per GB/month | 
Data transfers
Inbound data transfers i.e. data going into Azure data centers is free. Outbound data transfers i.e. data going out of Azure data centers from application gateway are charged at standard data transfer rates.
Azure Web Application Firewall (WAF) with Azure Front Door
Azure WAF adds additional security capabilities for Azure Front Door Premium - Web application and API protection, integration with Microsoft Threat Intelligence, Bot and DDoS protection, and security analytics. Azure WAF pricing is included with the Azure Front Door Premium. Please refer to Azure Front Door pricing page for details.
Azure Web Application Firewall (WAF) with Azure Front Door (classic) and Azure CDN from Microsoft (classic)
WAF pricing includes monthly fixed charges and request based processing charges. There is a monthly charge for each policy and add-on charges for Custom Rules and Managed Rulesets as configured in the policy.
Monthly fixed charge
| Price | |
|---|---|
| Policy | $5 per month | 
Add-on charges
| Custom Rules | Price | 
|---|---|
| Rules | $1 per month | 
| Requests Processed | $0.6 Per million requests | 
| Managed Ruleset | Price | 
|---|---|
| Default Ruleset | $20 per month | 
| Requests Processed | $1 Per million requests | 
Azure pricing and purchasing options
 
                
            Connect with us directly
Get a walkthrough of Azure pricing. Understand pricing for your cloud solution, learn about cost optimization and request a custom proposal.
Talk to a sales specialistSee ways to purchase
Purchase Azure services through the Azure website, a Microsoft representative, or an Azure partner.
Explore your optionsAdditional resources
Web Application Firewall
Learn more about Web Application Firewall features and capabilities.
Pricing calculator
Estimate your expected monthly costs for using any combination of Azure products.
SLA
Review the Service Level Agreement for Web Application Firewall.
Documentation
Review technical tutorials, videos, and more Web Application Firewall resources.
Frequently asked questions
- 
            
            Yes, a partial hour is billed as a full hour for Application Gateway.
- 
            
            Yes, there is a minimum response size that you will be billed for. For any traffic sent through Front Door, you will be billed for a minimum response size of 2KB which maps to your outbound data transfers. If the response size for a given request is less than 2KB, you will still be billed for 2KB.
- 
            
            Capacity Units measure consumption-based cost that is charged in addition to the fixed cost. Capacity unit charge is also computed hourly or partial hourly. There are three dimensions to capacity unit - compute unit, persistent connections, and throughput. Compute unit is a measure of processor capacity consumed. Please refer to our documentation page.
- 
            
            Both the WAF and WAF_v2 SKU include the use of WAF Policy and WAF rules at no additional cost.
Talk to a sales specialist for a walk-through of Azure pricing. Understand pricing for your cloud solution.
Get free cloud services and a $200 credit to explore Azure for 30 days.
