MicrosoftDocs/azure-docs/articles/ddos-protection

Last 20 commits touching this section.

3018333

Expand application DDoS protection guidance (#319387) * Revise DDoS protection article for clarity and detail Updated the title and description for clarity. Added new sections on defense layers and mitigation strategies for DDoS attacks, along with a checklist for baseline configuration. * Update articles/web-application-firewall/shared/application-ddos-protection.md Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * Update articles/web-application-firewall/shared/application-ddos-protection.md Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * Update articles/web-application-firewall/shared/application-ddos-protection.md Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * Update articles/web-application-firewall/shared/application-ddos-protection.md Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * Update articles/web-application-firewall/shared/application-ddos-protection.md Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com> * Refine application DDoS protection guidance * Refine DDoS article formatting and links * Refine related DDoS links * Add DDoS article applicability * Fix Application Gateway rate limit attribution * Move application DDoS article to WAF root * Refine DDoS article punctuation * Reorder DDoS article applicability * Fix DDoS article heading capitalization --------- Co-authored-by: joeolerich <113947519+joeolerich@users.noreply.github.com> Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com>

57d6f48

docs: correct list reference in types-of-attacks intro

ecf5c29

Apply Learn Authoring Assistant style suggestions

d4de02f

docs: align DDoS Protection scope, tier, and IP Protection quickstarts

4251452

docs: add Azure DDoS Protection custom policy (preview) doc set (#317595) Add concept, portal, Azure CLI, and ARM template how-tos for DDoS Protection custom policy (preview), plus TOC, overview, and features entry points and portal screenshots. Includes Learn Authoring Assistant style fixes. Co-authored-by: duau_microsoft <107149404+duau_microsoft@users.noreply.github.com>

57cd89c

Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/azure-docs (branch main) (#317274) * Update subscribe-to-graph-api-events.md Created event is not supported by Graph. https://learn.microsoft.com/en-us/graph/api/resources/subscription?view=graph-rest-1.0#properties * Fix typo in roleDefinitions function and update description Corrected a typo in the roleDefinitions function name and clarified the description regarding role definitions. * Update priority of custom rule example in WAF limits This is a typo instead of "0" we need to have "1". Basically, priority range for App GW custom WAF rule is 1-100, with 1 being the highest and 100 the lowest. * Testing repo sync on public repo (#128565) * Fix PHP Sample Code Service Connector (#128348) * CSS-Networking Update virtual-networks-udr-overview.md (#127980) I worked on a case there wasn't documentation on these other default routes therefore I added more default routes. I also added a sentence at the end of the "None" paragraph to explain that changing the default 0.0.0.0/0 "none" next hop will be removed. * Update MFA audit clarifying why the compliance list is always empty (#128340) Update MFA audit clarifying why the compliance list is always empty * FAQ: wrong answer (#128346) * Wrong Answer Current Information on Document: Can I create reverse DNS zones for both Azure Public and Private DNS? No. Reverse lookup zones are only supported for Azure Public DNS. But answer is wrong based on this Azure public document https://learn.microsoft.com/en-us/azure/dns/private-reverse-dns * Apply suggestion from @v-regandowner --------- Co-authored-by: Regan Downer <v-rdowner@microsoft.com> * Update to the available redundancy options explanation (#128388) * Update to the available redundancy options Updated the explanation of the available redundancy options. * Apply suggestion from @normesta Co-authored-by: Norm Estabrook <normesta@microsoft.com> --------- Co-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com> Co-authored-by: Norm Estabrook <normesta@microsoft.com> * Update DNS zone identifier range in documentation for single digit storage endpoints (#128211) * Update DNS zone identifier range in documentation * Address PR comment: Correct identifier range for DNS zone in documentation * Update articles/storage/common/storage-account-overview.md Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * Update key rotation details in secure-file-transfer-protocol-host-keys.md (#128570) * Update key rotation details in secure-file-transfer-protocol-host-keys.md Clarifying key rotation timelines and the rotation process in response to multiple questions. * Language update, additional clarification * Fix grammatical error in key rotation section * Clarify host key rotation process and timing Updated wording for clarity regarding host key rotation and timing. * Remove BreakingPoint Cloud as approved DDoS simulation partner (#128552) --------- Co-authored-by: akhudairymicrosoft <98033264+akhudairymicrosoft@users.noreply.github.com> Co-authored-by: Erwin <4255748+erwinkramer@users.noreply.github.com> Co-authored-by: Jagan Peddabavi <157447885+Jpeddabavi@users.noreply.github.com> Co-authored-by: learn-build-service-prod[bot] <113403604+learn-build-service-prod[bot]@users.noreply.github.com> Co-authored-by: Phil <v-jiakan@microsoft.com> Co-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com> Co-authored-by: Regan Downer <v-rdowner@microsoft.com> Co-authored-by: Huaping Yu <38988242+huypub@users.noreply.github.com> Co-authored-by: Learn Build Service GitHub App <Learn Build Service LearnBuild@microsoft.com> Co-authored-by: Jason Howell <5067358+JasonWHowell@users.noreply.github.com> Co-authored-by: disservin <disservin.social@gmail.com> Co-authored-by: carinaleonMS <carinaleon+github@microsoft.com> Co-authored-by: crisvaz-msft <93148358+crisvaz-msft@users.noreply.github.com> Co-authored-by: vikedesai <113926519+vikedesai@users.noreply.github.com> Co-authored-by: IVAN <ivanzhang1992@gmail.com> Co-authored-by: Norm Estabrook <normesta@microsoft.com> Co-authored-by: jorchiu <122116059+jorchiu@users.noreply.github.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-authored-by: asorrin-msft <asorrin@microsoft.com> Co-authored-by: ofirsar <66122664+ofirsar@users.noreply.github.com>

7de957d

networking-security-articles

5e31a89

Fact-check pass: fix factual errors and source citations across 6 networking security articles Two-pass fact-check review. Fixes from pass 1: - DDoS: Correct RBAC role (no 'Network Reader'); fix cost-protection wording (no registration); correct alert-template description; clarify IP vs Network Protection coverage; soften 'all public IPs' claim; retarget move-support link. - Network Watcher: Correct 'read-only observer' (packet capture installs extension); fix Sentinel detection list; clarify NSG vs VNet flow log retention; replace SAS rotation guidance with key-access guidance; note NSG flow log retirement context. - Traffic Manager: Fix broken degraded-status troubleshooting link; correct HTTPS probe claim (no cert validation); name 'Traffic Manager Contributor' role; remove fictitious 'profile identity'; correct Traffic View ECS claim. - NAT Gateway: Replace unsupported regional failover guidance with multi-region pattern; fix broken baseline link; clarify Azure Policy is Preview. - Private Link: Correct NAT port metric (PLS, not PE); fix Azure Policy naming (per-service built-ins); correct PLS subnet requirement (privateLinkServiceNetworkPolicies). - Route Server: Add missing Data protection section; add /26 subnet minimum; add branch-to-branch caveat; remove unverifiable hubRoutingPreference negative claim. Pass-2 refinements: - DDoS: Expand Event Hubs auth (shared access policy claims + trusted services). - Traffic Manager: Narrow service tag scope to Azure firewalls; add probe IP guidance for non-Azure endpoints. - Private Link: Soften custom RBAC permission list; qualify managed identity guidance. - Network Watcher: Remove unverified VNet-restriction caveat; narrow encryption scope to at-rest. - Route Server: Restore correct hubRoutingPreference Azure Policy alias guidance. Cross-cutting: Remove outdated per-service MCSB v1 baseline links from all 6 Next steps; update ms.date to 05/12/2026. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

f968c40

Convert site-relative links to relative markdown paths Use relative .md paths for same-repo links per Learn authoring guidelines. Cross-repo links (azure-monitor, entra, governance, well-architected, reliability, security-benchmark) remain site-relative. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

126be0a

Fix validation issues in security articles - DDoS Protection: Update stale Conditional Access link to Entra path - Private Link: Fix broken policy-reference link path - Network Watcher: Fix relative link to site-relative format, correct fabricated RBAC permission (packetCaptures/action → packetCaptures/write) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

c945264

Add secure-*.md articles to service TOC files Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

460743e

Add 6 networking 'secure your service' security articles New standalone security articles for networking services that were missing coverage: - articles/ddos-protection/secure-ddos-protection.md - articles/private-link/secure-private-link.md - articles/nat-gateway/secure-nat-gateway.md - articles/route-server/secure-route-server.md - articles/network-watcher/secure-network-watcher.md - articles/traffic-manager/secure-traffic-manager.md Each article follows the standard horz-security template with cross-links to the main networking overview and related sibling service security articles. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

82b8e4f

[migrate-content] Fix links

6f97b46

fix broken links

74d618c

docs: Update author metadata to duongau/duau for DDoS Protection articles

1e179f2

updated date.

21a905d

freshness update.

80a31a7

Merge pull request #311963 from AbdullahBell/ddos-best-practices Comprehensive update to DDoS Protection fundamental best practices

1edbf70

acrolinx

eb0dcca

fixed errors.