Refresh secure-application-gateway.md and secure-traffic-manager.md (SCI validator pass) (#318528)
* Refresh secure-application-gateway.md (SCI validator pass)
Structural uplevel:
- Frontmatter: ms.topic best-practice; ms.custom horz-security; ai-usage
ai-assisted; ms.date refreshed
- Author/ms.author set to SCI process owner (msmbaldwin/mbaldwin) per SCI
policy; docset owner continues to own underlying docs
- Added Zero Trust include
- Normalized bullets (* -> -)
- Renamed sections to canonical names: Monitoring and threat detection ->
Logging and monitoring; Asset management -> Compliance and governance
- Added Backup and recovery section
- Beefed up Identity and access management
- Preserved bespoke Web application protection section
Fact-check corrections:
- Removed Application Gateway Private Link preview hedging (now GA)
- Clarified WAF policy = Application Gateway WAF v2
- Corrected RBAC guidance: Network Contributor (no App Gateway-specific
built-in role)
- Updated TLS 1.2+ / end-to-end TLS wording
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629
* Refresh secure-traffic-manager.md (SCI validator pass)
- ms.date refresh
- Fact-check corrections:
- HTTPS probe wording tightened
- Subnet fallback behavior corrected to NODATA
- Updated links to exact supporting anchors for service tags,
cross-subscription endpoints, and RUM key/disable guidance
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629
* Iterative validator refinements (passes 2-8, converged clean 2x)
Ran azure-security-article-validator 7 additional times on both articles;
each iteration fed technical accuracy fixes back into the source. Passes
6 and 7 also exercised the newly-added Phase 1.2 'What's new' sweep,
which surfaced meaningful additions the initial refresh missed.
secure-application-gateway.md:
- Corrected diagnostic-logging bullet: activity log is automatic;
diagnostic settings collect access/WAF logs (perf logs v1-only)
- Fixed broken section anchor #alerts -> #application-gateway-alert-rules
- Refined TLS bullet to separate frontend TLS policy from backend HTTPS
settings (avoid implying frontend policy controls backend versions)
- Replaced unsupported Defender/WAF-specific claim with secure-score
posture guidance and accurate link
- Added WAF DRS-latest + log-mode validation recommendation (via
'What's new' sweep)
- Added preview WAF exceptions recommendation with scoping guidance
- Named current DRS version (DRS 2.2, was 2.1)
secure-traffic-manager.md:
- Added geographic-routing DNS-resolver caveat
- Clarified subnet routing uses source IP ranges; preserved NODATA
fallback wording
- Clarified HTTPS probes for web endpoints when appropriate
- Qualified cross-subscription endpoint guidance with Azure Web Apps
limitation
- Clarified Traffic Manager processes DNS queries typically via
recursive resolvers
- Added TLS 1.2+ enforcement recommendation for services interacting
with Traffic Manager (via 'What's new' sweep)
Known supporting-doc inconsistency: TM FAQ says NXDOMAIN for subnet
fallback; routing-methods doc says NODATA. Article uses NODATA (aligned
with routing-methods, the canonical reference). Docset owner to reconcile.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629
* Final-review polish (Dimension 1 style + Dimension 3 frontmatter)
Style-only fixes from the final-review skill sweep — no factual changes.
secure-application-gateway.md (4 fixes):
- Shortened description to <=160 chars
- Removed stacked punctuation after two `?`-terminated link texts
- 'security issues' -> 'security problems' (rule 17)
secure-traffic-manager.md (9 fixes):
- Shortened description
- Removed stacked punctuation after `?`-terminated link text
- 'centers on' -> 'focuses on' (rule 17)
- Backticked `MinChildEndpoints`; dropped 'is considered' (rules 24, 17)
- 'blast radius' -> 'impact' (rule 17)
- Rewrote passive/expanded 'cannot be used' (rules 3, 7)
- Fixed compound-subject verb agreement in 3 places (rule 8)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629
* Accept LAA suggestions and update skill
Application Gateway:
- L91: split '..., and review' compound predicate into two sentences
- L93: backtick AGWAccessLogs, AGWFirewallLogs, AGWPerformanceLogs
- L121: 'when resources were created manually' -> 'when you create resources manually'
Traffic Manager:
- L25: 'using the AzureTrafficManager service tag' -> 'by using ...';
'allowlist the published ... IP ranges' -> 'add ... to the allow list'
- L27: split '; note that probes ...' into two sentences
RUM key line already fixed in prior final-review polish (rewrote passive to active voice).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629
* Apply service-specificity rule and refresh
Contextualize cross-cutting IAM/governance bullets to name service-
specific resources, roles, and policies; swap generic overview links
for deeper service-specific targets where they exist. Add missing
private-only AGW deployment recommendation from What's new sweep.
Remove v1-only diagnostic details (v1 retired April 2026).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 315a6ea4-5e54-476a-8428-b2c4d8966175
* Add terminal period to Azure Resource Graph bullet (LAA)
Applies the outstanding Learn Authoring Assistant suggestion on the
Compliance and governance section.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8c037200-21e0-4f82-a724-0f30b764c98c
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629
Copilot-Session: 315a6ea4-5e54-476a-8428-b2c4d8966175
Copilot-Session: 8c037200-21e0-4f82-a724-0f30b764c98c