> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/web-application-and-api-protection-waap/integrations/waf-integrations/azure-integration.md).

# Azure integration

<details>

<summary>Updates (July 2026 to September 2026)</summary>

* *July 2026* — Updated the topic to add information about the sync-on-demand and schedule sync options for Azure WAF. For more information, see [Sync behavior](#sync-behavior).

</details>

Azure Web Application Firewall (WAF) is a cloud-based service from Microsoft Azure that helps protect web applications from common web threats and attacks. It acts as a reverse proxy, inspecting incoming web traffic to your web applications and filtering out malicious requests before they reach your application servers. Traceable integrates with Azure’s WAF to block IP addresses and threat actors.

## What will you learn in this topic?

By the end of this topic, you will be able to understand:

* An overview of the steps required to set up the Azure integration.
* The prerequisites for setting up the integration.
* The detailed steps for the integration.
* The management after configuring the integration.

***

## Integration overview

This section provides high-level information on integrating Azure WAF with Traceable and managing threats.

1. **Installation** — Traceable allows you to choose from an agent-less or agent-based deployment option. For more information on Traceable agents, see [Installation](https://docs.traceable.ai/docs/installation).
2. **Integration setup** — After deploying the agent, you can retrieve the credentials and configure the Azure integration. To do so, you must complete the following steps:
   1. **Prerequisites** — Log in to your Azure account and retrieve the necessary credentials, including the Azure tenant ID, subscription ID, client ID, and client secret. For more information, see [Before you begin](#before-you-begin).
   2. **Integration** — After obtaining the credentials from the previous steps, navigate to the Traceable platform and configure the integration. For more information, see [Set up the integration](#set-up-the-integration).
3. **Threat management** — After setting up the integration, you can establish rules to allow, block, or monitor IP addresses according to your specific requirements. Traceable's integration with Azure WAF supports the following two types of rules:
   1. **Threat Actors** — Any status change of threat actor on the Traceable Platform is propagated to Azure WAF. For example, if Traceable detects a threat actor and changes it to a deny state, requests from that threat actor can be blocked in Azure. Traceable recommends going through the allow list conditions before creating any IP-range rules. Traceable allows creating allowlists using allowed and snoozed states, and supports blocking using deny and suspended states under threat actors. For more information, see [IP address allowlist](https://docs.traceable.ai/docs/custom-policy#ip-address-allowlist). Moreover, if you make any changes, such as adding a threat actor to the allowlist or resolving the status, these changes are reflected in Azure within a few minutes.
   2. **Malicious source Rules** (**IP range** **only**) — If you configure any malicious source rules under **Protection** → **Policies** → **Custom Policies** → **Malicious Sources** tab to enforce blocking or allow for IP ranges to be executed through Azure.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Traceable’s Azure integration does not block IP addresses with <code>x-forwarded-for</code> and <code>x-real-ip</code> headers.</p></div>

The following is a high-level integration diagram:

<figure><img src="/files/RNLD56zbe7pZ5qhuoyoF" alt="" width="900"><figcaption><p>Traceable Azure Integration Diagram</p></figcaption></figure>

***

## Before you begin

Make a note of the following before proceeding with the integration steps:

* Reasonable knowledge of Azure WAF and policies in Azure.
* **Tenant ID** — In Microsoft Azure, a **Tenant ID**, also known as a Directory ID or a Directory Tenant ID, is a unique identifier for an Azure Active Directory (Azure AD) tenant. Azure AD is Microsoft's identity and access management service, which manages and secures access to Azure resources. To retrieve the Tenant ID, see [Tenant ID](https://learn.microsoft.com/en-us/azure/azure-portal/get-subscription-tenant-id).
* **Client ID** — A **Client ID**, or an Application ID, is a unique identifier associated with an application or service registered in Azure AD. This Client ID uniquely identifies and authenticates the application when it interacts with Azure AD for various purposes.
* **Client Secret** — A secret key associated with the Azure app registration, used by Traceable to obtain access tokens and authenticate API requests.
* **Azure Subscription ID** — A unique identifier for a specific Azure subscription. You can find your **Azure Subscription ID** in the Azure portal, typically in the subscription section. To retrieve the Tenant ID, see [Subscription ID](https://learn.microsoft.com/en-us/azure/azure-portal/get-subscription-tenant-id).
* The policies set by Traceable begin with the prefix *Traceable.*

***

## Set up the integration

To configure a new Azure integration, navigate to the Integrations page from the bottom left corner of your Traceable account, and do one of the following:

* Search for *Azure* in the search bar.
* Navigate to **WAF** → **Azure WAF**.

<figure><img src="/files/ilWFy0Rlwdq4X8BRqTvZ" alt="" width="750"><figcaption><p>Navigation</p></figcaption></figure>

In the **Azure WAF** tile, click **Configure**. In the **Add New Azure WAF Integration** slide-out panel, complete the following steps:

<figure><img src="/files/BD480D8IbW8VJLJdeZiG" alt="" width="450"><figcaption><p>Add New Azure WAF Integration</p></figcaption></figure>

1. Specify a unique **Name** for your integration, for example, *Azure\_WAF.*
2. (Optional) Specify a **Description** summary for your integration, for example, *Traceable\_integration.*
3. Specify the **Environments** for which you wish to integrate Azure from the drop-down list. These environments could be, for example, *production* or *QA*. You can choose one or more environments, or all of them.
4. Specify the **Azure Tenant ID**, which is a unique identifier associated with your Azure Active Directory tenant. For more information, see [Before you begin](#before-you-begin).
5. Specify the **Azure Subscription ID**, which is a unique identifier associated with your Azure subscription. For more information, see [Before you begin](#before-you-begin).
6. Specify the **Azure environment** used for the integration, such as *Azure*, *China*, or the *US government*.
7. Specify the **Client ID**, which is a unique identifier associated with the registered Azure application. For more information, see [Before you begin](#before-you-begin).
8. Specify the **Client Secret**, which is a secret key generated during Azure application registration and used for secure authentication.
9. In the **Azure** **Policy Details** section, specify the following policy details for Azure:

   <img src="/files/Y8DRZOulqlOLhu9BBTcl" alt="" width="590">

   1. **Azure WAF Policy Type** — The Azure WAF policy type used for the integration — Front Door ( Global WAF) or Application Gateway ( Regional WAF).

      Policy Name — The policy name associated with the chosen WAF configuration. The available policies are filtered based on the selected policy type.
   2. **Resource Group Name** — The name of the Azure resource group associated with the selected WAF policy, for example, *QA\_group*.
10. Click **Test Connection** to test the connection with Azure.
11. Click **Save** only after a successful test connection.

{% hint style="info" %}
You can add one or more than one integration for your chosen environment. The same policies are pushed to all the integrations across your chosen environment(s).
{% endhint %}

To verify the integration, check the rules in your Azure security policy. You can enable sync using the sync now option or schedule a sync in the update section. For more information, see [Managed configured integration](#viewing-configured-integration1).

***

## Manage configured integration

After configuring the integration, you can view the **Azure WAF Integration** under **Configured WAF Integrations**. Traceable gives you the flexibility to control how the integration operates. You can choose either of the following actions using the drop-down, according to your requirements:

* **Enabled** — You allow Traceable to actively update the WAF with the latest rules to enforce protection and monitor or block threats. When enabled, Traceable continuously sends new rules and updates to the WAF based on policy activity, helping enforce protections with the latest threat information and block suspicious traffic.
* **Disabled** — You stop Traceable from updating the WAF, so it no longer enforces new protections for that environment. When disabled, Traceable stops sending new rules and updates to the WAF for the selected environment while other environments continue using their existing integration settings without impact. The WAF continues to enforce existing rules based on their last applied state, without receiving new updates. Traceable continues to detect and evaluate threats, but it does not enforce them through WAF.

### Sync Behavior

After you create the integration, you can enable the sync option to push all the WAF rules simultaneously. It helps ensure that Azure WAF remains aligned with the new WAF rules configured in Traceable. The following table explains why you might need the scheduled synchronization or sync now option, when to use it, and how it helps maintain consistent rule enforcement between the platform and Azure WAF:

| **Why to use?**                                                                                                                                                                                                                                                                                                             | **When to use?**                                                                                                                                                                                         | **How can you leverage it?**                                                                                                                                                                                                                                                                         |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| You can use this capability to keep Azure WAF aligned with the latest Traceable rule configuration. It helps prevent security gaps caused by integration downtime, missed synchronizations, or rule changes that are not automatically propagated, reducing configuration drift and ensuring consistent policy enforcement. | You can use this option when you create or update supported rules while the Azure WAF integration is disabled, or when you configure a new Azure WAF integration after rules already exist in Traceable. | You can configure a synchronization schedule that automatically reviews supported rules and reconciles any differences between Traceable and Azure WAF. At the defined interval, Traceable applies missing updates and deploys the latest supported rule configuration to keep Azure WAF up to date. |

**Synchronization direction** — Scheduled Synchronization operates in a single direction from Traceable to Azure WAF. During each synchronization cycle, Traceable pushes the supported rule configuration to Azure WAF to ensure it reflects the latest Traceable state.

#### Scheduled sync and sync now

Both synchronization options update Azure WAF with supported rules from Traceable, but they serve different purposes.

<figure><img src="/files/ZIPFPsWTapceHKQlcj55" alt="" width="750"><figcaption><p>Sync Now Option for configured WAF integration</p></figcaption></figure>

To enable the sync option, you can choose one of the following options discussed in the table below, according to your requirements:

| **Option**         | **Description**                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Sync Now**       | Immediately synchronizes supported rules with Azure WAF on demand. You can click **Sync Now** from the **Ellipse** (![](/files/zSOFfNAAGfurCmsG8mY3)) **icon** when an immediate update is required.                                                                                                                                                                                            |
| **Scheduled Sync** | Automatically synchronizes supported rules at a defined recurring interval. To configure it, navigate to the **Configured WAF Integrations** and enable the **Scheduled Sync** toggle. This ensures Azure WAF remains continuously aligned with Traceable configuration without manual intervention. For more information, see [Configure schedule sync](#configure-scheduled-synchronization). |

***

#### Configure scheduled sync

To enable **Scheduled Sync**, complete the following steps:

<figure><img src="/files/TwuEiBX9JHi4ZEJUpSSN" alt="" width="490"><figcaption><p>Scheduled Sync</p></figcaption></figure>

1. Navigate to the **Configured WAF integrations**.
2. Click **Azure WAF**.
3. In the **Update Azure WAF Integration** slide-out panel, on the **Update Integration** step, click **Next**.
4. On the **Sync** step, enable the **Scheduled Sync** toggle.
5. Set the synchronization frequency by selecting the **Frequency**, **Day**, and **Time** according to your requirements.
6. Click **Save**.

After you save the configuration, Traceable automatically runs synchronization according to the schedule you define.
