[{"author":"msmbaldwin","date":"2026-08-13T17:36:54+00:00","message":"Refresh secure-application-gateway.md and secure-traffic-manager.md (SCI validator pass) (#318528)\n\n* Refresh secure-application-gateway.md (SCI validator pass)\n\nStructural uplevel:\n- Frontmatter: ms.topic best-practice; ms.custom horz-security; ai-usage\n  ai-assisted; ms.date refreshed\n- Author/ms.author set to SCI process owner (msmbaldwin/mbaldwin) per SCI\n  policy; docset owner continues to own underlying docs\n- Added Zero Trust include\n- Normalized bullets (* -> -)\n- Renamed sections to canonical names: Monitoring and threat detection ->\n  Logging and monitoring; Asset management -> Compliance and governance\n- Added Backup and recovery section\n- Beefed up Identity and access management\n- Preserved bespoke Web application protection section\n\nFact-check corrections:\n- Removed Application Gateway Private Link preview hedging (now GA)\n- Clarified WAF policy = Application Gateway WAF v2\n- Corrected RBAC guidance: Network Contributor (no App Gateway-specific\n  built-in role)\n- Updated TLS 1.2+ / end-to-end TLS wording\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629\n\n* Refresh secure-traffic-manager.md (SCI validator pass)\n\n- ms.date refresh\n- Fact-check corrections:\n  - HTTPS probe wording tightened\n  - Subnet fallback behavior corrected to NODATA\n  - Updated links to exact supporting anchors for service tags,\n    cross-subscription endpoints, and RUM key/disable guidance\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629\n\n* Iterative validator refinements (passes 2-8, converged clean 2x)\n\nRan azure-security-article-validator 7 additional times on both articles;\neach iteration fed technical accuracy fixes back into the source. Passes\n6 and 7 also exercised the newly-added Phase 1.2 'What's new' sweep,\nwhich surfaced meaningful additions the initial refresh missed.\n\nsecure-application-gateway.md:\n- Corrected diagnostic-logging bullet: activity log is automatic;\n  diagnostic settings collect access/WAF logs (perf logs v1-only)\n- Fixed broken section anchor #alerts -> #application-gateway-alert-rules\n- Refined TLS bullet to separate frontend TLS policy from backend HTTPS\n  settings (avoid implying frontend policy controls backend versions)\n- Replaced unsupported Defender/WAF-specific claim with secure-score\n  posture guidance and accurate link\n- Added WAF DRS-latest + log-mode validation recommendation (via\n  'What's new' sweep)\n- Added preview WAF exceptions recommendation with scoping guidance\n- Named current DRS version (DRS 2.2, was 2.1)\n\nsecure-traffic-manager.md:\n- Added geographic-routing DNS-resolver caveat\n- Clarified subnet routing uses source IP ranges; preserved NODATA\n  fallback wording\n- Clarified HTTPS probes for web endpoints when appropriate\n- Qualified cross-subscription endpoint guidance with Azure Web Apps\n  limitation\n- Clarified Traffic Manager processes DNS queries typically via\n  recursive resolvers\n- Added TLS 1.2+ enforcement recommendation for services interacting\n  with Traffic Manager (via 'What's new' sweep)\n\nKnown supporting-doc inconsistency: TM FAQ says NXDOMAIN for subnet\nfallback; routing-methods doc says NODATA. Article uses NODATA (aligned\nwith routing-methods, the canonical reference). Docset owner to reconcile.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629\n\n* Final-review polish (Dimension 1 style + Dimension 3 frontmatter)\n\nStyle-only fixes from the final-review skill sweep \u2014 no factual changes.\n\nsecure-application-gateway.md (4 fixes):\n- Shortened description to <=160 chars\n- Removed stacked punctuation after two `?`-terminated link texts\n- 'security issues' -> 'security problems' (rule 17)\n\nsecure-traffic-manager.md (9 fixes):\n- Shortened description\n- Removed stacked punctuation after `?`-terminated link text\n- 'centers on' -> 'focuses on' (rule 17)\n- Backticked `MinChildEndpoints`; dropped 'is considered' (rules 24, 17)\n- 'blast radius' -> 'impact' (rule 17)\n- Rewrote passive/expanded 'cannot be used' (rules 3, 7)\n- Fixed compound-subject verb agreement in 3 places (rule 8)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629\n\n* Accept LAA suggestions and update skill\n\nApplication Gateway:\n- L91: split '..., and review' compound predicate into two sentences\n- L93: backtick AGWAccessLogs, AGWFirewallLogs, AGWPerformanceLogs\n- L121: 'when resources were created manually' -> 'when you create resources manually'\n\nTraffic Manager:\n- L25: 'using the AzureTrafficManager service tag' -> 'by using ...';\n  'allowlist the published ... IP ranges' -> 'add ... to the allow list'\n- L27: split '; note that probes ...' into two sentences\n\nRUM key line already fixed in prior final-review polish (rewrote passive to active voice).\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629\n\n* Apply service-specificity rule and refresh\n\nContextualize cross-cutting IAM/governance bullets to name service-\nspecific resources, roles, and policies; swap generic overview links\nfor deeper service-specific targets where they exist. Add missing\nprivate-only AGW deployment recommendation from What's new sweep.\nRemove v1-only diagnostic details (v1 retired April 2026).\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 315a6ea4-5e54-476a-8428-b2c4d8966175\n\n* Add terminal period to Azure Resource Graph bullet (LAA)\n\nApplies the outstanding Learn Authoring Assistant suggestion on the\nCompliance and governance section.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 8c037200-21e0-4f82-a724-0f30b764c98c\n\n---------\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 960e9f77-c754-413f-8e31-3e7c083b9629\nCopilot-Session: 315a6ea4-5e54-476a-8428-b2c4d8966175\nCopilot-Session: 8c037200-21e0-4f82-a724-0f30b764c98c","sha":"c7f0b99ec9d7fba8a1028b529aa6b28080d001ea","url":"https://github.com/MicrosoftDocs/azure-docs/commit/c7f0b99ec9d7fba8a1028b529aa6b28080d001ea"},{"author":"asudbring","date":"2026-08-12T07:18:46+00:00","message":"docs: set endpoint -Priority in Traffic Manager PowerShell quickstart (#319293)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"e4af3f45681265a844774f001ecbf365af147053","url":"https://github.com/MicrosoftDocs/azure-docs/commit/e4af3f45681265a844774f001ecbf365af147053"},{"author":"prmerger-automator","date":"2026-08-12T00:45:59+00:00","message":"Merge pull request #319296 from asudbring/asudbring/tm-powershell-arm-routing-methods-599143\n\nList all six routing methods in TrafficRoutingMethod description","sha":"6077a25af2e84659aeb5925e562e2cf7e049cf2b","url":"https://github.com/MicrosoftDocs/azure-docs/commit/6077a25af2e84659aeb5925e562e2cf7e049cf2b"},{"author":"prmerger-automator","date":"2026-08-12T00:37:23+00:00","message":"Merge pull request #319306 from asudbring/asudbring/dns-record-types-multivalue-599144\n\nfix: reconcile DNS record types note with MultiValue IPv4/IPv6 behavior (F-3127)","sha":"ffb6f2ffa064d2cf451e3ced4393bab09a8d3fd4","url":"https://github.com/MicrosoftDocs/azure-docs/commit/ffb6f2ffa064d2cf451e3ced4393bab09a8d3fd4"},{"author":"prmerger-automator","date":"2026-08-12T00:37:01+00:00","message":"Merge pull request #319305 from asudbring/asudbring/tm-dns-name-standardize-599141\n\nfix: standardize Traffic Manager DNS name output value and format (F-3102)","sha":"a7676fdedcfc21c211f62485e4d14a395ae74d5a","url":"https://github.com/MicrosoftDocs/azure-docs/commit/a7676fdedcfc21c211f62485e4d14a395ae74d5a"},{"author":"asudbring","date":"2026-08-12T00:36:50+00:00","message":"Update ms.date\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"a6b6d1012d4d7b4eb911393b464a24368627222f","url":"https://github.com/MicrosoftDocs/azure-docs/commit/a6b6d1012d4d7b4eb911393b464a24368627222f"},{"author":"prmerger-automator","date":"2026-08-12T00:24:12+00:00","message":"Merge pull request #319295 from asudbring/asudbring/tm-subnet-routing-ws2019-599142\n\nAlign subnet routing test VMs to Windows Server 2019","sha":"d060fbc9cd353f521653776d23c8a07b38e39cd5","url":"https://github.com/MicrosoftDocs/azure-docs/commit/d060fbc9cd353f521653776d23c8a07b38e39cd5"},{"author":"prmerger-automator","date":"2026-08-12T00:23:51+00:00","message":"Merge pull request #319304 from asudbring/asudbring/multivalue-template-minchild-599140\n\nCorrect mislabeled MultiValue ARM template article (nested endpoints/min-child)","sha":"64bd3376e62743ab58923ca7d9448eef1eb5393b","url":"https://github.com/MicrosoftDocs/azure-docs/commit/64bd3376e62743ab58923ca7d9448eef1eb5393b"},{"author":"prmerger-automator","date":"2026-08-12T00:23:30+00:00","message":"Merge pull request #319297 from asudbring/asudbring/tm-rum-vs-android-scope-599145\n\nScope RUM Android-only note to App Center mobile SDK","sha":"1dc2390e962de60b99b1d8d56fc6e34247a96d9d","url":"https://github.com/MicrosoftDocs/azure-docs/commit/1dc2390e962de60b99b1d8d56fc6e34247a96d9d"},{"author":"asudbring","date":"2026-08-12T00:00:44+00:00","message":"Apply Authoring Assistant suggestions\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"a94731628f2010f261f270ac722466103ae3f384","url":"https://github.com/MicrosoftDocs/azure-docs/commit/a94731628f2010f261f270ac722466103ae3f384"},{"author":"asudbring","date":"2026-08-12T00:00:16+00:00","message":"Apply Authoring Assistant suggestion\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"0fcd66395d42148fc88b33c5b02df9d62ac64c9b","url":"https://github.com/MicrosoftDocs/azure-docs/commit/0fcd66395d42148fc88b33c5b02df9d62ac64c9b"},{"author":"asudbring","date":"2026-08-11T23:51:56+00:00","message":"Apply Authoring Assistant suggestion\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"5b657f674aec1615d7c34c6ac33f7286f3cb9462","url":"https://github.com/MicrosoftDocs/azure-docs/commit/5b657f674aec1615d7c34c6ac33f7286f3cb9462"},{"author":"asudbring","date":"2026-08-11T23:51:41+00:00","message":"Apply Authoring Assistant suggestion\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"cb41f1872dd0506b3c3c72fb8c39071fd32189ad","url":"https://github.com/MicrosoftDocs/azure-docs/commit/cb41f1872dd0506b3c3c72fb8c39071fd32189ad"},{"author":"asudbring","date":"2026-08-11T23:50:59+00:00","message":"Apply Authoring Assistant suggestion\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"c00a31f4ae5d8c3d572e0ae4853dd326925f1ad1","url":"https://github.com/MicrosoftDocs/azure-docs/commit/c00a31f4ae5d8c3d572e0ae4853dd326925f1ad1"},{"author":"asudbring","date":"2026-08-11T23:46:23+00:00","message":"Scope the MultiValue note to documented behavior\n\nRemove the unsourced assertion about per-query record type filtering and\nkeep the documented MultiValue and nested profile requirements.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"c255f721d61c3d564e606bde28682acf1093c215","url":"https://github.com/MicrosoftDocs/azure-docs/commit/c255f721d61c3d564e606bde28682acf1093c215"},{"author":"asudbring","date":"2026-08-11T23:45:43+00:00","message":"Note EDNS Client Subnet handling for subnet override\n\nWhen a resolver passes ECS information, Traffic Manager matches on the\nclient subnet rather than the DNS query source IP.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"57d14930e70d0e166f6f1c8971b3b586e78af7e6","url":"https://github.com/MicrosoftDocs/azure-docs/commit/57d14930e70d0e166f6f1c8971b3b586e78af7e6"},{"author":"asudbring","date":"2026-08-11T23:44:33+00:00","message":"Correct MultiValue casing to match the PowerShell parameter\n\nNew-AzTrafficManagerProfile -TrafficRoutingMethod accepts MultiValue with\na capital V, matching the Traffic Manager ARM schema enum.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"a39533b03b916b210933e5a3f91d65c49155d747","url":"https://github.com/MicrosoftDocs/azure-docs/commit/a39533b03b916b210933e5a3f91d65c49155d747"},{"author":"asudbring","date":"2026-08-11T03:58:38+00:00","message":"fix: reconcile DNS record types note with MultiValue IPv4/IPv6 behavior\n\nScope the single-record-type restriction and document that a MultiValue\nprofile can hold both IPv4 (A) and IPv6 (AAAA) address endpoints, and that\nnested MultiValue profiles require at least one IPv4 and one IPv6 endpoint.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"23fc4256ff07e90fc291ccf3c7b9fc39d3e9e949","url":"https://github.com/MicrosoftDocs/azure-docs/commit/23fc4256ff07e90fc291ccf3c7b9fc39d3e9e949"},{"author":"asudbring","date":"2026-08-11T03:55:13+00:00","message":"fix: correct garbled profile DNS name in subnet routing method table\n\nThe Name setting now states the profile name must be unique within the\ntrafficmanager.net zone and results in the DNS name <name>.trafficmanager.net.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"f6ceaa423ffc128beb8a6ae3b65a0cda3bed4f81","url":"https://github.com/MicrosoftDocs/azure-docs/commit/f6ceaa423ffc128beb8a6ae3b65a0cda3bed4f81"},{"author":"asudbring","date":"2026-08-11T03:55:12+00:00","message":"fix: correct DNS name output value and format in Traffic Manager CLI quickstart\n\nCopy the fqdn value (matching the az ... --query dnsConfig.fqdn command)\ninstead of RelativeDnsName, and express the DNS name as\n<relativednsname>.trafficmanager.net without http:// in the definition.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"bbf96b32265406f4f73d0fbd6e04485412aca482","url":"https://github.com/MicrosoftDocs/azure-docs/commit/bbf96b32265406f4f73d0fbd6e04485412aca482"}]
