Skip to content
Security waf

Web Application Firewall (WAF) policy naming convention

The CAF abbreviation for Web Application Firewall (WAF) policy is waf. Names can be 1 to 128 characters long and allow alphanumerics only. The name must be unique within the resource group.

Naming rules

CAF abbreviation waf
Length 1 to 128 characters
Allowed characters Alphanumerics (a-z, A-Z, 0-9)
Scope of uniqueness Unique within the resource group
CAF pattern waf{workload}{environment}{region}{instance}
Worth knowing: Start with a letter.

Rules follow Microsoft's resource naming rules and CAF abbreviations. Some resource types have extra start/end character restrictions, so verify against the official docs before locking in a convention.

Naming Security resources

Key Vault has its own guide covering its strict 24 character global uniqueness and soft delete name reservation. Managed identities are cheap to create and usually provisioned per app or per function rather than shared, so unlike most of this list, their naming should tie tightly to the specific workload they are attached to.

VPN Gateway and Bastion resources are typically one per hub or region rather than one per environment, name them for the network boundary they protect. The common mistake is naming managed identities generically, id-prod for example, when dozens end up in the same subscription and it becomes impossible to tell which resource an identity actually belongs to.

Example names

Generated by the same engine as the name generator, so length and character rules are already applied.

Scenario Generated name Length
Payments API, production wafpaymentsprodeus001 21/128
Web app, development wafwebappdevweu002 18/128
Analytics with company prefix wafcontosoanalyticsstageuks001 30/128

Naming in Terraform and Bicep

Build the name from variables so one module produces the right name in every environment.

Terraform
locals {
  waf_policy_name = "waf${var.workload}${var.environment}${var.region}001"
}
Bicep
var wafPolicyName = 'waf${workload}${environment}${region}001'

Generate Web Application Firewall (WAF) policy names for your workload

Free, no login. Validation and Terraform, Bicep, or CSV export included.

Open in the generator →

Related Security resources

See the full list of Azure resource naming rules or read the complete CAF naming guide.