Skip to content
Security waf

Web Application Firewall (WAF) policy naming convention

The CAF abbreviation for Web Application Firewall (WAF) policy is waf. Names can be 1 to 128 characters long and allow alphanumerics only. The name must be unique within the resource group.

Naming rules

CAF abbreviation waf
Length 1 to 128 characters
Allowed characters Alphanumerics (a-z, A-Z, 0-9)
Scope of uniqueness Unique within the resource group
CAF pattern waf{workload}{environment}{region}{instance}
Worth knowing: Start with a letter.

Rules follow Microsoft's resource naming rules and CAF abbreviations. Some resource types have extra start/end character restrictions, so verify against the official docs before locking in a convention.

Example names

Generated by the same engine as the name generator, so length and character rules are already applied.

Scenario Generated name Length
Payments API, production wafpaymentsprodeus001 21/128
Web app, development wafwebappdevweu002 18/128
Analytics with company prefix wafcontosoanalyticsstageuks001 30/128

Naming in Terraform and Bicep

Build the name from variables so one module produces the right name in every environment.

Terraform
locals {
  waf_policy_name = "waf${var.workload}${var.environment}${var.region}001"
}
Bicep
var wafPolicyName = 'waf${workload}${environment}${region}001'

Generate Web Application Firewall (WAF) policy names for your workload

Free, no login. Validation and Terraform, Bicep, or CSV export included.

Open in the generator →

Related Security resources

See the full list of Azure resource naming rules or read the complete CAF naming guide.