Azure Firewall Gets Threat Intelligence
Threat intelligence-based filtering can be enabled for your firewall to alert and deny traffic from/to known malicious IP addresses and domains. The IP addresses and domains are sourced from the Microsoft Threat Intelligence feed. By default, threat intelligence-based filtering is enabled in alert mode. A service tag represents a group of IP address prefixes for specific Microsoft services such as SQL Azure, Azure Key Vault, and Azure Service Bus, to simplify network rule creation. Azure Firewall users today can configure the service to alert and deny traffic to and from known malicious IP addresses and domains in near real-time. Moreover, the firewall service receives a feed of Microsoft's threat intelligence, which includes these addresses and domains.









