---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Azure Web Application Firewall Policy

# Azure Web Application Firewall Policy pattern-based discovery {#ariaid-title1}

* Release version: Yokohama
* 
* Updated August 11, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Azure Web Application Firewall Policy pattern-based discovery

Azure Web Application Firewall Policy pattern-based discovery uses ServiceNow's Discovery and Service Mapping Patterns application to identify and map Azure Web Application Firewall (WAF) policies within your cloud environment.
This discovery enables you to populate relevant data into your Configuration Management Database (CMDB) and related non-CMDB tables for comprehensive visibility and management of Azure WAF policies.
Show full answer Show less  
To leverage this capability, ensure you meet Microsoft Azure discovery prerequisites and enable the specific discovery pattern. Note that from Visibility Content version 6.28.0 onward, enabling or disabling patterns no longer counts as a customization and patterns reset to the latest version after upgrades while retaining their active status.

## Key Features

* **Pattern Activation:** The Azure Web Application Firewall Policy pattern is disabled by default and requires manual activation.
* **GovCloud Support:** Discovering Azure GovCloud (US) resources requires configuring the Azure service account with the appropriate datacenter URL.
* **Data Population:** The discovery populates data into both CMDB and non-CMDB tables to capture comprehensive details about WAF policies.
* **Non-CMDB Data:** The *Azure - Web Application Firewall Policy - Extended Inventory (LP)* pattern fills non-CMDB tables with detailed resource attributes such as object ID, kind, location, resource group, subscription ID, tenant ID, provisioning state, policy state, and references to related Web ACL CIs.
* **CMDB Data:** The same pattern populates CMDB tables with Web ACL information including unique identifiers, names, locations, default actions (allow or detect), install and operational status, and resource descriptions.
* **CI Relationships:** The pattern establishes relationships between Web ACLs and other configuration items like Cloud Load Balancers, Resource Groups, and Azure Datacenters to model dependencies and hosting.
* **Tag Discovery:** Azure tags are collected and stored in the Key Value table, linking tag names and values for enhanced metadata management.

## Practical Benefits for ServiceNow Customers

* Gain automated and accurate discovery of Azure Web Application Firewall policies to maintain an up-to-date CMDB.
* Understand policy operational modes (Prevention vs. Detection) to support security posture assessments.
* Visualize relationships between WAF policies, load balancers, resource groups, and datacenters to improve impact analysis and change management.
* Leverage Azure tags within ServiceNow for better filtering, reporting, and governance of cloud resources.
* Enable discovery of Azure GovCloud resources by configuring service accounts correctly, ensuring comprehensive coverage of your cloud environment.  
Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.

## Pattern-based discovery and mapping requirements {#azure-web-app-firewall-policy__selection_ipy_53n_jfc}

Verify the Microsoft Azure discovery prerequisites{#azure-web-app-firewall-policy__verify-azure-discovery-prerequisites-dlentry}
:   For more information, see the prerequisites section in [Microsoft Azure Cloud components discovery using patterns](https://servicenow-prod.fluidtopics.net/JeDZ0tlC9eLF5fei5qSv3w "Discovery uses multiple patterns to discover components of the Microsoft Azure Cloud deployment during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.").

Enable the relevant pattern{#azure-web-app-firewall-policy__enable-pattern-reuse-dlentry}
:   The pattern for this service is disabled by default. Starting with Visibility Content version 6.28.0, activating or deactivating a pattern won't be considered a customization, and it will continue to receive updates. Patterns that were previously activated or deactivated will reset to the latest predefined version after upgrading while retaining the last active field value. For more information on enabling patterns, see [Activate a disabled pattern](https://servicenow-prod.fluidtopics.net/R5W5GP640V_5uNIhVNRPCw "If you want to use a pattern for discovery that's disabled by default, activate it manually.").{#azure-web-app-firewall-policy__activating-disabled-pattern-not-customization}

Configure the Discovery schedule to support GovCloud{#azure-web-app-firewall-policy__configure-govcloud-azure-dlentry}
:   Discovering Azure GovCloud (US) accounts requires using a datacenter URL when setting up an Azure service account. For more information, see [Set up Azure service accounts](https://servicenow-prod.fluidtopics.net/wA59_lRoV_0PzpuODHnNjA "Create and configure cloud service accounts at ServiceNow AI Platform for the corresponding Microsoft Azure accounts.").{#azure-web-app-firewall-policy__configure-govcloud-azure-dd}
{#azure-web-app-firewall-policy__configure-govcloud-azure-dd} Discovery and Service Mapping Patterns application populates data in both CMDB and non-CMDB tables.

## Data stored in non-CMDB tables {#azure-web-app-firewall-policy__section_aq4_qkq_hfc}

Discovery and Service Mapping Patterns application populates data in the non-CMDB table when running the Azure - Web Application Firewall Policy - Extended Inventory(LP) pattern.

You can review the non-CMDB
Azure tables by navigating to AllConfigurationAzure. You can also search the navigation filter for the specific pattern name.  
{#azure-web-app-firewall-policy__section_aq4_qkq_hfc__entry__2}

| Field | Description |
|-|-|
| Object Id \[object_id\] | The unique identifier of the resource. |
| Kind \[kind\] | The specific kind or variant of the resource. |
| DC Location \[location\] | The Azure region where the resource is deployed. |
| Resource Group \[resource_group\] | The name of the resource group containing the resource. |
| Subscription Id \[subscription_id\] | The subscription ID associated with the resource. |
| Tenant Id \[tenant_id\] | The Azure Active Directory tenant ID associated with the resource. |
| Provisioning State \[provisioning_state\] | The latest provisioning status of the resource. |
| Configuration Item \[configuration_item\] | References the Web ACL \[cmdb_ci_web_acl\] table. |
| Policy State \[policy_state\] | The current state of the policy applied to the resource. |
[Table 1. Azure Web Application Firewall - Policy \[cmdb_azure_web_application_firewall_policy\]]

## Data stored in CMDB tables

Discovery and Service Mapping Patterns application populates data in the CMDB when running the Azure - Web Application Firewall Policy - Extended Inventory(LP) pattern.  
{#azure-web-app-firewall-policy__entry__22}

| Field | Description |
|-|-|
| Object ID \[object_id\] | The unique identifier of the resource. |
| Name \[name\] | The name of the resource. |
| Location \[location\] | The Azure region where the resource is deployed. |
| Default Action \[default_action\] | Indicates the effective operation mode of the web application firewall (WAF) policy. Possible values are allow and detect. * allow: policy is running in Prevention mode and is blocking traffic * detect: policy is running in Detection mode and is logging only {#azure-web-app-firewall-policy__ul_a11_sxs_ghc} |
| Install Status \[install_status\] | Install status of the resource. Default value is Installed. |
| Operational status \[operational_status\] | Operational status of the resource. Default value is Operational. |
| Description \[short_description\] | Type of resource. The value is set to microsoft.network/applicationgatewaywebapplicationfirewallpolicies. |
[Table 2. Web ACL \[cmdb_ci_web_acl\]]

## CI relationships

The Azure - Web Application Firewall Policy - Extended Inventory(LP) pattern creates these relationships to support Azure Web Application Firewall Policy discovery.  
{#azure-web-app-firewall-policy__entry__39}

| CI | Relationship | CI |
|-|-|-|
| Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] | Protected by::Protects | Web ACL \[cmdb_ci_web_acl\] |
| Resource Group \[cmdb_ci_resource_group\] | Contains::Contained by | Web ACL \[cmdb_ci_web_acl\] |
| Web ACL \[cmdb_ci_web_acl\] | Hosted on::Hosts | Azure Datacenter \[cmdb_ci_azure_datacenter\] |
| Azure Web Application Firewall - Policy \[cmdb_azure_web_application_firewall_policy\] | References | Web ACL \[cmdb_ci_web_acl\] |
[ ]

## Azure tag discovery {#azure-web-app-firewall-policy__section_ezc_jwt_jfc}

The pattern collects tags and populates them in the Key Value \[cmdb_key_value\] table. {#azure-web-app-firewall-policy__table_axq_spc_y2c__entry__2}

| Field | Description |
|-|-|
| Key \[key\] | Tag name. |
| Value \[value\] | Tag value. |
[Table 3. Key Value \[cmdb_key_value\]]

{#azure-web-app-firewall-policy__table_axq_spc_y2c}

*[\>]: and then


