[{"author":"halkazwini","date":"2026-08-13T17:30:55+00:00","message":"Expand application DDoS protection guidance (#319387)\n\n* Revise DDoS protection article for clarity and detail\n\nUpdated the title and description for clarity. Added new sections on defense layers and mitigation strategies for DDoS attacks, along with a checklist for baseline configuration.\n\n* Update articles/web-application-firewall/shared/application-ddos-protection.md\n\nCo-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com>\n\n* Update articles/web-application-firewall/shared/application-ddos-protection.md\n\nCo-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com>\n\n* Update articles/web-application-firewall/shared/application-ddos-protection.md\n\nCo-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com>\n\n* Update articles/web-application-firewall/shared/application-ddos-protection.md\n\nCo-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com>\n\n* Update articles/web-application-firewall/shared/application-ddos-protection.md\n\nCo-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com>\nCo-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com>\n\n* Refine application DDoS protection guidance\n\n* Refine DDoS article formatting and links\n\n* Refine related DDoS links\n\n* Add DDoS article applicability\n\n* Fix Application Gateway rate limit attribution\n\n* Move application DDoS article to WAF root\n\n* Refine DDoS article punctuation\n\n* Reorder DDoS article applicability\n\n* Fix DDoS article heading capitalization\n\n---------\n\nCo-authored-by: joeolerich <113947519+joeolerich@users.noreply.github.com>\nCo-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com>\nCo-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com>","sha":"3018333ed1a03524e2f765eeaba9278da829d48e","url":"https://github.com/MicrosoftDocs/azure-docs/commit/3018333ed1a03524e2f765eeaba9278da829d48e"},{"author":"duongau","date":"2026-08-01T00:01:27+00:00","message":"docs: correct list reference in types-of-attacks intro","sha":"57d6f483133ba2e878b07cd2394faf39a4fc6842","url":"https://github.com/MicrosoftDocs/azure-docs/commit/57d6f483133ba2e878b07cd2394faf39a4fc6842"},{"author":"duongau","date":"2026-07-31T23:52:33+00:00","message":"Apply Learn Authoring Assistant style suggestions","sha":"ecf5c29ac98f7bd2c0f19b70dd783d67b33256ce","url":"https://github.com/MicrosoftDocs/azure-docs/commit/ecf5c29ac98f7bd2c0f19b70dd783d67b33256ce"},{"author":"duongau","date":"2026-07-31T21:27:32+00:00","message":"docs: align DDoS Protection scope, tier, and IP Protection quickstarts","sha":"d4de02f535fa93a70addea91d7e34156a410f64e","url":"https://github.com/MicrosoftDocs/azure-docs/commit/d4de02f535fa93a70addea91d7e34156a410f64e"},{"author":"duongau","date":"2026-07-22T18:51:15+00:00","message":"docs: add Azure DDoS Protection custom policy (preview) doc set (#317595)\n\nAdd concept, portal, Azure CLI, and ARM template how-tos for DDoS Protection custom policy (preview), plus TOC, overview, and features entry points and portal screenshots. Includes Learn Authoring Assistant style fixes.\n\nCo-authored-by: duau_microsoft <107149404+duau_microsoft@users.noreply.github.com>","sha":"4251452d0a53f9c2ec402eec056cfec75e36d0da","url":"https://github.com/MicrosoftDocs/azure-docs/commit/4251452d0a53f9c2ec402eec056cfec75e36d0da"},{"author":"learn-build-service-prod","date":"2026-06-17T21:48:06+00:00","message":"Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/azure-docs (branch main) (#317274)\n\n* Update subscribe-to-graph-api-events.md\n\nCreated event is not supported by Graph. https://learn.microsoft.com/en-us/graph/api/resources/subscription?view=graph-rest-1.0#properties\n\n* Fix typo in roleDefinitions function and update description\n\nCorrected a typo in the roleDefinitions function name and clarified the description regarding role definitions.\n\n* Update priority of custom rule example in WAF limits\n\nThis is a typo instead of \"0\" we need to have \"1\". \nBasically, priority range for App GW custom WAF rule is 1-100, with 1 being the highest and 100 the lowest.\n\n* Testing repo sync on public repo (#128565)\n\n* Fix PHP Sample Code Service Connector (#128348)\n\n* CSS-Networking Update virtual-networks-udr-overview.md (#127980)\n\nI worked on a case there wasn't documentation on these other default routes therefore I added more default routes. I also added a sentence at the end of the \"None\" paragraph to explain that changing the default 0.0.0.0/0 \"none\" next hop will be removed.\n\n* Update MFA audit clarifying why the compliance list is always empty (#128340)\n\nUpdate MFA audit clarifying why the compliance list is always empty\n\n* FAQ: wrong answer (#128346)\n\n* Wrong Answer\n\nCurrent Information on Document:\n\nCan I create reverse DNS zones for both Azure Public and Private DNS?\nNo. Reverse lookup zones are only supported for Azure Public DNS.\n\nBut answer is wrong based on this Azure public document https://learn.microsoft.com/en-us/azure/dns/private-reverse-dns\n\n* Apply suggestion from @v-regandowner\n\n---------\n\nCo-authored-by: Regan Downer <v-rdowner@microsoft.com>\n\n* Update to the available redundancy options explanation (#128388)\n\n* Update to the available redundancy options\n\nUpdated the explanation of the available redundancy options.\n\n* Apply suggestion from @normesta\n\nCo-authored-by: Norm Estabrook <normesta@microsoft.com>\n\n---------\n\nCo-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com>\nCo-authored-by: Norm Estabrook <normesta@microsoft.com>\n\n* Update DNS zone identifier range in documentation for single digit storage endpoints (#128211)\n\n* Update DNS zone identifier range in documentation\n\n* Address PR comment: Correct identifier range for DNS zone in documentation\n\n* Update articles/storage/common/storage-account-overview.md\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\n\n* Update key rotation details in secure-file-transfer-protocol-host-keys.md (#128570)\n\n* Update key rotation details in secure-file-transfer-protocol-host-keys.md\n\nClarifying key rotation timelines and the rotation process in response to multiple questions.\n\n* Language update, additional clarification\n\n* Fix grammatical error in key rotation section\n\n* Clarify host key rotation process and timing\n\nUpdated wording for clarity regarding host key rotation and timing.\n\n* Remove BreakingPoint Cloud as approved DDoS simulation partner (#128552)\n\n---------\n\nCo-authored-by: akhudairymicrosoft <98033264+akhudairymicrosoft@users.noreply.github.com>\nCo-authored-by: Erwin <4255748+erwinkramer@users.noreply.github.com>\nCo-authored-by: Jagan Peddabavi <157447885+Jpeddabavi@users.noreply.github.com>\nCo-authored-by: learn-build-service-prod[bot] <113403604+learn-build-service-prod[bot]@users.noreply.github.com>\nCo-authored-by: Phil <v-jiakan@microsoft.com>\nCo-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com>\nCo-authored-by: Regan Downer <v-rdowner@microsoft.com>\nCo-authored-by: Huaping Yu <38988242+huypub@users.noreply.github.com>\nCo-authored-by: Learn Build Service GitHub App <Learn Build Service LearnBuild@microsoft.com>\nCo-authored-by: Jason Howell <5067358+JasonWHowell@users.noreply.github.com>\nCo-authored-by: disservin <disservin.social@gmail.com>\nCo-authored-by: carinaleonMS <carinaleon+github@microsoft.com>\nCo-authored-by: crisvaz-msft <93148358+crisvaz-msft@users.noreply.github.com>\nCo-authored-by: vikedesai <113926519+vikedesai@users.noreply.github.com>\nCo-authored-by: IVAN <ivanzhang1992@gmail.com>\nCo-authored-by: Norm Estabrook <normesta@microsoft.com>\nCo-authored-by: jorchiu <122116059+jorchiu@users.noreply.github.com>\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\nCo-authored-by: asorrin-msft <asorrin@microsoft.com>\nCo-authored-by: ofirsar <66122664+ofirsar@users.noreply.github.com>","sha":"57cd89c915aa15029d8f8b7a4216067b1b18ffc6","url":"https://github.com/MicrosoftDocs/azure-docs/commit/57cd89c915aa15029d8f8b7a4216067b1b18ffc6"},{"author":"msmbaldwin","date":"2026-06-03T19:37:16+00:00","message":"networking-security-articles","sha":"7de957dfadd128a48f21f559b0ebc9ad44dd7c29","url":"https://github.com/MicrosoftDocs/azure-docs/commit/7de957dfadd128a48f21f559b0ebc9ad44dd7c29"},{"author":"msmbaldwin","date":"2026-05-12T17:21:11+00:00","message":"Fact-check pass: fix factual errors and source citations across 6 networking security articles\n\nTwo-pass fact-check review. Fixes from pass 1:\n- DDoS: Correct RBAC role (no 'Network Reader'); fix cost-protection wording (no registration);\n  correct alert-template description; clarify IP vs Network Protection coverage; soften 'all\n  public IPs' claim; retarget move-support link.\n- Network Watcher: Correct 'read-only observer' (packet capture installs extension); fix\n  Sentinel detection list; clarify NSG vs VNet flow log retention; replace SAS rotation\n  guidance with key-access guidance; note NSG flow log retirement context.\n- Traffic Manager: Fix broken degraded-status troubleshooting link; correct HTTPS probe\n  claim (no cert validation); name 'Traffic Manager Contributor' role; remove fictitious\n  'profile identity'; correct Traffic View ECS claim.\n- NAT Gateway: Replace unsupported regional failover guidance with multi-region pattern;\n  fix broken baseline link; clarify Azure Policy is Preview.\n- Private Link: Correct NAT port metric (PLS, not PE); fix Azure Policy naming (per-service\n  built-ins); correct PLS subnet requirement (privateLinkServiceNetworkPolicies).\n- Route Server: Add missing Data protection section; add /26 subnet minimum; add\n  branch-to-branch caveat; remove unverifiable hubRoutingPreference negative claim.\n\nPass-2 refinements:\n- DDoS: Expand Event Hubs auth (shared access policy claims + trusted services).\n- Traffic Manager: Narrow service tag scope to Azure firewalls; add probe IP guidance for\n  non-Azure endpoints.\n- Private Link: Soften custom RBAC permission list; qualify managed identity guidance.\n- Network Watcher: Remove unverified VNet-restriction caveat; narrow encryption scope to at-rest.\n- Route Server: Restore correct hubRoutingPreference Azure Policy alias guidance.\n\nCross-cutting: Remove outdated per-service MCSB v1 baseline links from all 6 Next steps;\nupdate ms.date to 05/12/2026.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"5e31a891977fe61e482cf7fb27a70a9056f2c3e3","url":"https://github.com/MicrosoftDocs/azure-docs/commit/5e31a891977fe61e482cf7fb27a70a9056f2c3e3"},{"author":"msmbaldwin","date":"2026-04-23T21:15:58+00:00","message":"Convert site-relative links to relative markdown paths\n\nUse relative .md paths for same-repo links per Learn authoring guidelines.\nCross-repo links (azure-monitor, entra, governance, well-architected,\nreliability, security-benchmark) remain site-relative.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"f968c406e17e7003b4cf4d538edbdca295f87242","url":"https://github.com/MicrosoftDocs/azure-docs/commit/f968c406e17e7003b4cf4d538edbdca295f87242"},{"author":"msmbaldwin","date":"2026-04-23T21:07:14+00:00","message":"Fix validation issues in security articles\n\n- DDoS Protection: Update stale Conditional Access link to Entra path\n- Private Link: Fix broken policy-reference link path\n- Network Watcher: Fix relative link to site-relative format, correct\n  fabricated RBAC permission (packetCaptures/action \u2192 packetCaptures/write)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"126be0af9202f6d568ec897831732192f457a00e","url":"https://github.com/MicrosoftDocs/azure-docs/commit/126be0af9202f6d568ec897831732192f457a00e"},{"author":"msmbaldwin","date":"2026-04-23T21:03:09+00:00","message":"Add secure-*.md articles to service TOC files\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"c945264c0915c57a603aed5aa3d83a84ea3a82d7","url":"https://github.com/MicrosoftDocs/azure-docs/commit/c945264c0915c57a603aed5aa3d83a84ea3a82d7"},{"author":"msmbaldwin","date":"2026-04-23T20:32:19+00:00","message":"Add 6 networking 'secure your service' security articles\n\nNew standalone security articles for networking services that were\nmissing coverage:\n\n- articles/ddos-protection/secure-ddos-protection.md\n- articles/private-link/secure-private-link.md\n- articles/nat-gateway/secure-nat-gateway.md\n- articles/route-server/secure-route-server.md\n- articles/network-watcher/secure-network-watcher.md\n- articles/traffic-manager/secure-traffic-manager.md\n\nEach article follows the standard horz-security template with\ncross-links to the main networking overview and related sibling\nservice security articles.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"460743ea44c4b22b7e37a7538f0960dd7ab7c1c1","url":"https://github.com/MicrosoftDocs/azure-docs/commit/460743ea44c4b22b7e37a7538f0960dd7ab7c1c1"},{"author":"ge-bsc-fte","date":"2026-04-20T18:52:18+00:00","message":"[migrate-content] Fix links","sha":"82b8e4f803342c1a495447ec5f161ceec8e33ea1","url":"https://github.com/MicrosoftDocs/azure-docs/commit/82b8e4f803342c1a495447ec5f161ceec8e33ea1"},{"author":"v-thepet","date":"2026-04-03T01:23:15+00:00","message":"fix broken links","sha":"6f97b462fc3c07afb102b7a353214aa418734ada","url":"https://github.com/MicrosoftDocs/azure-docs/commit/6f97b462fc3c07afb102b7a353214aa418734ada"},{"author":"duongau","date":"2026-04-02T00:10:02+00:00","message":"docs: Update author metadata to duongau/duau for DDoS Protection articles","sha":"74d618cd9a1e3f0b7cc3c9eda25fee82794a67ed","url":"https://github.com/MicrosoftDocs/azure-docs/commit/74d618cd9a1e3f0b7cc3c9eda25fee82794a67ed"},{"author":"abdullah.bell","date":"2026-03-17T18:13:26+00:00","message":"updated date.","sha":"1e179f26df73be504c2549523e0df628a26043f6","url":"https://github.com/MicrosoftDocs/azure-docs/commit/1e179f26df73be504c2549523e0df628a26043f6"},{"author":"abdullah.bell","date":"2026-03-17T18:00:28+00:00","message":"freshness update.","sha":"21a905d29076af15d78a4c7559d076d98ffb0468","url":"https://github.com/MicrosoftDocs/azure-docs/commit/21a905d29076af15d78a4c7559d076d98ffb0468"},{"author":"v-dirichards","date":"2026-03-06T16:35:45+00:00","message":"Merge pull request #311963 from AbdullahBell/ddos-best-practices\n\nComprehensive update to DDoS Protection fundamental best practices","sha":"80a31a763587969769a2f358e887959067878e6e","url":"https://github.com/MicrosoftDocs/azure-docs/commit/80a31a763587969769a2f358e887959067878e6e"},{"author":"v-dirichards","date":"2026-03-06T16:11:47+00:00","message":"acrolinx","sha":"1edbf70d88e8c40316207831b7d78839457a6d75","url":"https://github.com/MicrosoftDocs/azure-docs/commit/1edbf70d88e8c40316207831b7d78839457a6d75"},{"author":"abdullah.bell","date":"2026-03-05T20:33:11+00:00","message":"fixed errors.","sha":"eb0dccaa8232e161334e06a4d1976c97cc9a41d6","url":"https://github.com/MicrosoftDocs/azure-docs/commit/eb0dccaa8232e161334e06a4d1976c97cc9a41d6"}]
