Skip to content
Search Sign in List your company

Azure Firewall

by Microsoft Azure from Microsoft

Page last updated
26 August 2026
What these mean

Report a problem with this product

Price on request

Azure Firewall is Microsoft Azure's managed cloud-native network firewall for stateful traffic inspection, centralized policy enforcement, threat intelligence, and advanced network security across Azure virtual networks.

About Azure Firewall

Azure Firewall is Microsoft Azure's managed cloud-native network firewall for inspecting and controlling traffic across Azure virtual networks. It provides stateful Layer 3 through Layer 7 filtering, network and application rules, NAT, threat intelligence, centralized policy management, and built-in high availability. Microsoft currently offers Basic, Standard, and Premium SKUs. The right choice depends on required throughput, threat protection, inspection depth, policy scale, and whether features such as DNS proxy, web categories, TLS inspection, IDPS, or URL filtering are required.

What is included

SKUs

Basic, Standard, Premium Basic targets smaller environments, Standard adds enterprise filtering and threat intelligence, and Premium adds TLS inspection, IDPS and URL filtering.

Filtering

Stateful L3-L7 rules Supports stateful network, application and NAT rule processing across Azure virtual network traffic.

Threat protection

Threat intelligence Standard and Premium can alert on or deny traffic to known malicious IP addresses and domains using Microsoft threat intelligence.

Premium security

TLS inspection and IDPS Premium adds outbound TLS inspection and a managed intrusion detection and prevention system for deeper traffic inspection.

Management

Firewall Policy and Firewall Manager Supports reusable Firewall Policy resources and centralized multi-firewall management through Azure Firewall Manager.

Performance

Autoscaling throughput Microsoft documents Basic up to 250 Mbps, Standard up to 30 Gbps and Premium up to 100 Gbps, subject to workload and inspection settings.

Pricing

Fixed plus variable billing Billing combines a fixed deployment charge per firewall hour with a variable data processing charge per GB; optional prescaling capacity adds another meter.

What is Azure Firewall used for?

Azure Firewall is used to centralize network traffic inspection and policy enforcement in Azure. Common scenarios include filtering outbound internet access from application subnets, controlling inbound traffic through DNAT rules, inspecting east-west traffic between networks, enforcing organization-wide network rules, and routing traffic through one managed firewall in a hub-and-spoke design.

The service is fully stateful, so it tracks connections rather than treating every packet independently. Microsoft documents application rules for FQDN and HTTP or HTTPS scenarios, network rules for IP, port, and protocol filtering, and NAT rules for address translation. This makes Azure Firewall broader than a Network Security Group, but it also introduces more cost and design complexity than simple subnet-level filtering.

How do Basic, Standard, and Premium differ?

Microsoft currently offers Azure Firewall Basic, Standard, and Premium. Basic is intended for smaller environments and Microsoft documents throughput up to 250 Mbps. It includes core stateful filtering, NAT, logging, built-in high availability, and centralized management. Threat intelligence is available in alert mode.

Standard adds more enterprise features, including network-level FQDN filtering, threat intelligence alert and deny, DNS proxy, custom DNS, and web categories. Microsoft documents autoscaling up to 30 Gbps for Standard. Premium adds advanced inspection for sensitive workloads, including TLS inspection, a managed intrusion detection and prevention system, URL filtering, and higher performance. Microsoft currently documents Premium scaling up to 100 Gbps, subject to inspection mode and workload characteristics.

How should organizations deploy Azure Firewall?

Microsoft commonly documents Azure Firewall in a central hub virtual network with application or spoke networks routed through it. The firewall uses a dedicated AzureFirewallSubnet, and workload route tables direct selected traffic to the firewall for inspection. This pattern can simplify centralized policy management across many networks and subscriptions.

Hub placement does not remove network architecture work. Teams still need to plan address spaces, routes, DNS, public and private IPs, peering, forced tunneling where required, availability zones, and how traffic returns from the destination. Microsoft also notes that global virtual network peering is not generally recommended as a substitute for regional firewall placement because cross-region latency and performance can become a concern.

How do Firewall Policy and Firewall Manager fit in?

Azure Firewall Policy separates rule configuration from the firewall resource and can be reused across supported firewall deployments. Policies can contain DNAT, network, and application rule collections, along with SKU-specific settings such as DNS, threat intelligence, web categories, and Premium inspection features.

Azure Firewall Manager provides centralized policy and routing management for multiple firewalls and secured virtual hubs. This is useful for larger environments where central platform teams need shared base policies while application teams still require controlled local rules. Centralization can reduce configuration drift, but policy inheritance and change ownership should be documented so teams understand which rule is responsible for allowing or denying a flow.

What security features matter most in Premium?

Azure Firewall Premium is designed for organizations that need deeper inspection than domain and network filtering alone. Microsoft currently documents TLS inspection for outbound traffic, a managed IDPS, URL filtering, and web categories. TLS inspection decrypts supported encrypted traffic, inspects it, and then re-encrypts it before forwarding.

These capabilities add security depth but also increase operational responsibility. TLS inspection requires certificate planning and can affect applications that use certificate pinning or uncommon TLS behavior. IDPS signatures can generate false positives and should be tuned. Teams should test Premium inspection with representative applications and monitor denied or alerted traffic before enabling broad blocking policies.

How does Azure Firewall pricing work?

Azure Firewall does not have one flat monthly price. Microsoft's current pricing page describes two core cost components for Basic, Standard, and Premium: a fixed deployment charge billed per firewall per hour and a variable data processing charge billed per gigabyte of traffic processed. Standard and Premium can also use optional Capacity Units for prescaling, which add an hourly capacity meter when explicitly configured.

Pricing was checked on August 26, 2026. Exact rates depend on region, agreement, currency, SKU, traffic volume, and whether prescaling is used. Buyers should also include adjacent Azure costs such as public IPs, logging, Log Analytics ingestion, network bandwidth, routing, and any complementary security services. A centralized firewall can simplify operations, but sending every flow through it can also increase both latency and cost.

What are the main limitations and operational tradeoffs?

Azure Firewall is managed, but it is still a central network dependency. Routing mistakes, overly broad deny rules, DNS misconfiguration, insufficient testing, or unexpected application behavior can affect many workloads at once. Autoscaling also takes time, so Microsoft recommends performance testing over several minutes rather than assuming scale appears instantly during a sudden spike.

The service is not a replacement for every security control. Network Security Groups remain useful for subnet and network-interface segmentation, Web Application Firewall is designed for web application attacks, and identity or application authorization still needs to be enforced separately. Premium inspection can also reduce effective throughput when features such as IDPS deny mode and TLS inspection are active.

Who should choose something else?

Small environments that only need simple allow and deny rules between subnets may be adequately served by Network Security Groups and platform routing without the cost of a managed firewall. Web applications that mainly need protection from SQL injection, cross-site scripting, and other HTTP attacks should evaluate Azure Web Application Firewall on Application Gateway or Front Door rather than relying on a network firewall alone.

Organizations that require a specific third-party firewall ecosystem, specialized inspection engine, or existing vendor policy framework may prefer a network virtual appliance. Azure Firewall is strongest when teams want an Azure-native managed firewall with centralized policy, built-in high availability, Azure integration, and a clear progression from Basic to Standard to Premium security capabilities.

Reviews

No reviews yet

Nobody has reviewed Azure Firewall here yet.