SOP-35: Azure Firewall Threat Intelligence Alert

Detection and response procedures for Azure Firewall threat intelligence deny events and IDPS signature matches. Covers AzureDiagnostics parsing for TI deny logs, Azure Firewall Premium IDPS severity analysis, and the critical distinction between blocked TI traffic and IDPS alerts in Alert mode.

2026-08-15T09:46:01.825Z
Rudra Verma, Senior Security Architect & Researcher