Announcing public preview of A... Note

Announcing public preview of Azure DDoS Protection custom policy

Azure DDoS Protection has launched a public preview of a new custom policy feature, offering users more control over attack detection and mitigation. This new capability allows customers to fine-tune mitigation behavior and configure protocol-specific detection thresholds for protected workloads. It addresses the need for organizations with unique traffic characteristics, such as latency-sensitive applications or predictable traffic spikes, to customize protection. Advantages include granular control over TCP, UDP, and TCP SYN traffic thresholds, enabling alignment with anticipated traffic changes during events. The feature maintains flexibility while benefiting from Azure's global-scale mitigation infrastructure and allows per-resource policy management for different environments. Customers also retain full operational visibility through existing Azure Monitor and DDoS Protection telemetry. Deployment and management of custom policies are available through the Azure portal, supporting Standard Load Balancer frontend IP configurations. Current limitations include support only for Standard Load Balancer frontend IPs and no PowerShell support. Users should carefully select thresholds based on anticipated traffic baselines, starting with conservative changes and validating behavior in lower environments. While custom policies disable autotuning for configured protocols, autotuning remains active where no custom threshold is set. This enhancement provides an optional override to Azure DDoS Protection's existing automatic and adaptive engine.