MicrosoftDocs/azure-docs/articles/traffic-manager

Last 20 commits touching this section.

c7f0b99

Refresh secure-application-gateway.md and secure-traffic-manager.md (SCI validator pass) (#318528) * Refresh secure-application-gateway.md (SCI validator pass) Structural uplevel: - Frontmatter: ms.topic best-practice; ms.custom horz-security; ai-usage ai-assisted; ms.date refreshed - Author/ms.author set to SCI process owner (msmbaldwin/mbaldwin) per SCI policy; docset owner continues to own underlying docs - Added Zero Trust include - Normalized bullets (* -> -) - Renamed sections to canonical names: Monitoring and threat detection -> Logging and monitoring; Asset management -> Compliance and governance - Added Backup and recovery section - Beefed up Identity and access management - Preserved bespoke Web application protection section Fact-check corrections: - Removed Application Gateway Private Link preview hedging (now GA) - Clarified WAF policy = Application Gateway WAF v2 - Corrected RBAC guidance: Network Contributor (no App Gateway-specific built-in role) - Updated TLS 1.2+ / end-to-end TLS wording Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629 * Refresh secure-traffic-manager.md (SCI validator pass) - ms.date refresh - Fact-check corrections: - HTTPS probe wording tightened - Subnet fallback behavior corrected to NODATA - Updated links to exact supporting anchors for service tags, cross-subscription endpoints, and RUM key/disable guidance Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629 * Iterative validator refinements (passes 2-8, converged clean 2x) Ran azure-security-article-validator 7 additional times on both articles; each iteration fed technical accuracy fixes back into the source. Passes 6 and 7 also exercised the newly-added Phase 1.2 'What's new' sweep, which surfaced meaningful additions the initial refresh missed. secure-application-gateway.md: - Corrected diagnostic-logging bullet: activity log is automatic; diagnostic settings collect access/WAF logs (perf logs v1-only) - Fixed broken section anchor #alerts -> #application-gateway-alert-rules - Refined TLS bullet to separate frontend TLS policy from backend HTTPS settings (avoid implying frontend policy controls backend versions) - Replaced unsupported Defender/WAF-specific claim with secure-score posture guidance and accurate link - Added WAF DRS-latest + log-mode validation recommendation (via 'What's new' sweep) - Added preview WAF exceptions recommendation with scoping guidance - Named current DRS version (DRS 2.2, was 2.1) secure-traffic-manager.md: - Added geographic-routing DNS-resolver caveat - Clarified subnet routing uses source IP ranges; preserved NODATA fallback wording - Clarified HTTPS probes for web endpoints when appropriate - Qualified cross-subscription endpoint guidance with Azure Web Apps limitation - Clarified Traffic Manager processes DNS queries typically via recursive resolvers - Added TLS 1.2+ enforcement recommendation for services interacting with Traffic Manager (via 'What's new' sweep) Known supporting-doc inconsistency: TM FAQ says NXDOMAIN for subnet fallback; routing-methods doc says NODATA. Article uses NODATA (aligned with routing-methods, the canonical reference). Docset owner to reconcile. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629 * Final-review polish (Dimension 1 style + Dimension 3 frontmatter) Style-only fixes from the final-review skill sweep — no factual changes. secure-application-gateway.md (4 fixes): - Shortened description to <=160 chars - Removed stacked punctuation after two `?`-terminated link texts - 'security issues' -> 'security problems' (rule 17) secure-traffic-manager.md (9 fixes): - Shortened description - Removed stacked punctuation after `?`-terminated link text - 'centers on' -> 'focuses on' (rule 17) - Backticked `MinChildEndpoints`; dropped 'is considered' (rules 24, 17) - 'blast radius' -> 'impact' (rule 17) - Rewrote passive/expanded 'cannot be used' (rules 3, 7) - Fixed compound-subject verb agreement in 3 places (rule 8) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629 * Accept LAA suggestions and update skill Application Gateway: - L91: split '..., and review' compound predicate into two sentences - L93: backtick AGWAccessLogs, AGWFirewallLogs, AGWPerformanceLogs - L121: 'when resources were created manually' -> 'when you create resources manually' Traffic Manager: - L25: 'using the AzureTrafficManager service tag' -> 'by using ...'; 'allowlist the published ... IP ranges' -> 'add ... to the allow list' - L27: split '; note that probes ...' into two sentences RUM key line already fixed in prior final-review polish (rewrote passive to active voice). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629 * Apply service-specificity rule and refresh Contextualize cross-cutting IAM/governance bullets to name service- specific resources, roles, and policies; swap generic overview links for deeper service-specific targets where they exist. Add missing private-only AGW deployment recommendation from What's new sweep. Remove v1-only diagnostic details (v1 retired April 2026). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 315a6ea4-5e54-476a-8428-b2c4d8966175 * Add terminal period to Azure Resource Graph bullet (LAA) Applies the outstanding Learn Authoring Assistant suggestion on the Compliance and governance section. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c037200-21e0-4f82-a724-0f30b764c98c --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629 Copilot-Session: 315a6ea4-5e54-476a-8428-b2c4d8966175 Copilot-Session: 8c037200-21e0-4f82-a724-0f30b764c98c

e4af3f4

docs: set endpoint -Priority in Traffic Manager PowerShell quickstart (#319293) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

6077a25

Merge pull request #319296 from asudbring/asudbring/tm-powershell-arm-routing-methods-599143 List all six routing methods in TrafficRoutingMethod description

ffb6f2f

Merge pull request #319306 from asudbring/asudbring/dns-record-types-multivalue-599144 fix: reconcile DNS record types note with MultiValue IPv4/IPv6 behavior (F-3127)

a7676fd

Merge pull request #319305 from asudbring/asudbring/tm-dns-name-standardize-599141 fix: standardize Traffic Manager DNS name output value and format (F-3102)

a6b6d10

Update ms.date Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

d060fbc

Merge pull request #319295 from asudbring/asudbring/tm-subnet-routing-ws2019-599142 Align subnet routing test VMs to Windows Server 2019

64bd337

Merge pull request #319304 from asudbring/asudbring/multivalue-template-minchild-599140 Correct mislabeled MultiValue ARM template article (nested endpoints/min-child)

1dc2390

Merge pull request #319297 from asudbring/asudbring/tm-rum-vs-android-scope-599145 Scope RUM Android-only note to App Center mobile SDK

a947316

Apply Authoring Assistant suggestions Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

0fcd663

Apply Authoring Assistant suggestion Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

5b657f6

Apply Authoring Assistant suggestion Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

cb41f18

Apply Authoring Assistant suggestion Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

c00a31f

Apply Authoring Assistant suggestion Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

c255f72

Scope the MultiValue note to documented behavior Remove the unsourced assertion about per-query record type filtering and keep the documented MultiValue and nested profile requirements. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

57d1493

Note EDNS Client Subnet handling for subnet override When a resolver passes ECS information, Traffic Manager matches on the client subnet rather than the DNS query source IP. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

a39533b

Correct MultiValue casing to match the PowerShell parameter New-AzTrafficManagerProfile -TrafficRoutingMethod accepts MultiValue with a capital V, matching the Traffic Manager ARM schema enum. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

23fc425

fix: reconcile DNS record types note with MultiValue IPv4/IPv6 behavior Scope the single-record-type restriction and document that a MultiValue profile can hold both IPv4 (A) and IPv6 (AAAA) address endpoints, and that nested MultiValue profiles require at least one IPv4 and one IPv6 endpoint. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

f6ceaa4

fix: correct garbled profile DNS name in subnet routing method table The Name setting now states the profile name must be unique within the trafficmanager.net zone and results in the DNS name <name>.trafficmanager.net. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

bbf96b3

fix: correct DNS name output value and format in Traffic Manager CLI quickstart Copy the fqdn value (matching the az ... --query dnsConfig.fqdn command) instead of RelativeDnsName, and express the DNS name as <relativednsname>.trafficmanager.net without http:// in the definition. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>