Azure Firewall Manager is a centralized management platform for network security policies in Azure. The service enables unified configuration of Azure Firewall across multiple hubs, VNets, and subscriptions.
What is Azure Firewall Manager?
Azure Firewall Manager provides a central interface for managing firewall policies, routing, and security configurations. Instead of configuring each Azure Firewall individually, administrators can define policies centrally and apply them to multiple firewalls.
The service supports two architecture types: hub virtual networks (a classic, self-managed hub-and-spoke topology with Azure Firewall Policy) and secured virtual hubs (Azure Virtual WAN hubs with security and routing policies). Both options enable centralized traffic routing through Azure Firewall.
Core Features
- Central firewall deployment: Configure multiple Azure Firewall instances across different regions and subscriptions
- Hierarchical policies: Global base policies at the enterprise level with locally overridable policies for individual teams
- Security partner integration: Optional integration of a security-as-a-service provider (currently Zscaler) for internet traffic filtering in secured virtual hubs
- Centralized routing: Automatic routing of traffic to the secured hub without manual user-defined routes
- DDoS protection: Association of DDoS protection plans with virtual networks
- WAF policy management: Centralized management of Web Application Firewall policies for Azure Front Door and Application Gateway
Typical Use Cases
Firewall Manager suits enterprises with multiple Azure subscriptions and regions that need unified security policies. The service is ideal for hub-and-spoke architectures and Azure Virtual WAN deployments with centralized governance across multiple teams.
Benefits
- Unified security policies across all Azure Firewalls and WAF policies
- Reduced administration overhead through centralized management instead of individual configuration
- Governance through hierarchical policy inheritance (global and local)
- Integration with Azure Virtual WAN for globally distributed networks
Integration with innFactory
As a Microsoft Solutions Partner, innFactory supports you with Azure Firewall Manager: network security design, hub-and-spoke architectures, Virtual WAN setup, and security governance.
Typical Use Cases
Frequently Asked Questions
What is the difference between Azure Firewall Manager and Azure Firewall?
Azure Firewall is the actual firewall service that filters traffic. Firewall Manager is the centralized management layer for firewall policies, routing, and WAF policies across multiple firewalls, hubs, and subscriptions.
Does Azure Firewall Manager cost extra?
No, Azure Firewall Manager itself doesn't add extra cost. You pay for the Azure Firewall instances, the traffic that flows through them, and any linked services such as Web Application Firewall or DDoS protection plans.
Can I integrate third-party security providers?
Yes, in Secured Virtual Hubs you can additionally filter internet traffic through a security-as-a-service partner. Zscaler is currently the supported partner; the scope of partner integrations can change, so it's worth checking the current documentation.
What are Secured Virtual Hubs?
Secured Virtual Hubs are Azure Virtual WAN hubs with an attached Azure Firewall or security partner solution. They enable centralized security routing for traffic between VNets, branches, and the internet, without manual user-defined routes.
What else can I manage centrally through Firewall Manager?
In addition to firewall policies, you can also centrally manage Web Application Firewall policies for Azure Front Door and Application Gateway, as well as the association of DDoS protection plans with virtual networks.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
