Introduction
As organizations migrate workloads to Microsoft Azure, controlling outbound internet traffic has become an essential part of their cloud security strategy. Organizations need visibility into outbound connections, centralized traffic filtering, application-level access control, and detailed logging to meet security and compliance requirements.
Azure Firewall Explicit Proxy provides a way to address these requirements by allowing applications, virtual machines, and other proxy-aware clients to send HTTP and HTTPS traffic directly to Azure Firewall using its private IP address.
Unlike traditional transparent firewall deployments, which rely on User Defined Routes (UDRs) to direct traffic through the firewall, Explicit Proxy allows applications to specify Azure Firewall as their forward proxy. This enables centralized outbound traffic control without requiring UDR-based redirection for those proxy-configured connections.
This article explains Azure Firewall Explicit Proxy, its architecture, configuration using the Azure portal and Azure CLI, client-side proxy settings, security considerations, monitoring, and troubleshooting.
1. What is Azure Firewall Explicit Proxy?
Azure Firewall Explicit Proxy is a forward proxy capability that allows HTTP and HTTPS-aware applications to connect to Azure Firewall through a configured proxy address.
In a conventional transparent firewall deployment, network traffic is routed through the firewall using UDRs. The client does not need to know that a firewall is intercepting its traffic.
With Explicit Proxy, the application is explicitly configured to use the firewall’s private IP address and designated proxy port.
Transparent proxy vs. Explicit Proxy
|
Feature |
Transparent firewall |
Explicit Proxy |
|---|---|---|
|
Client configuration |
Not required |
Required |
|
Traffic steering |
Typically uses UDRs |
Application proxy settings |
|
Protocol support |
Depends on firewall rules and configuration |
HTTP and HTTPS |
|
Application awareness |
No proxy configuration needed |
Proxy-aware application |
|
Centralized filtering |
Yes |
Yes, through application rules |
|
PAC file support |
Not applicable to transparent routing |
Supported |
|
Application-level proxy selection |
No |
Yes |
Azure Firewall Explicit Proxy is configured through an associated Firewall Policy and is supported by Azure Firewall Standard and Premium.
2. Azure Firewall Explicit Proxy Architecture
The following architecture illustrates how workload applications connect to Azure Firewall through an explicit proxy endpoint, how firewall policy controls outbound access, and how an optional Proxy Auto-Configuration (PAC) file can distribute client proxy settings.

Architecture components
-
Workload subnet: Contains Windows and Linux virtual machines, application servers, and proxy-aware applications.
-
Azure Virtual Network (VNet): Provides private connectivity between workloads and Azure Firewall.
-
Azure Firewall: Receives explicit HTTP/HTTPS proxy requests on its configured private IP address and proxy ports.
-
Firewall Policy: Defines application rules, allowed destination FQDNs, protocols, and traffic governance.
-
Azure Blob Storage (optional): Hosts a PAC file that clients can use to determine which traffic should go through the proxy.
-
Internet and SaaS applications: External destinations such as websites, Microsoft 365, and other approved cloud services.
-
Azure Monitor: Collects diagnostic and application rule logs for visibility, auditing, and troubleshooting.
Traffic flow
-
A workload application is configured to use Azure Firewall’s private IP and explicit proxy port, either manually or through a PAC file.
-
The application sends an HTTP request or HTTPS CONNECT request to the proxy listener.
-
Azure Firewall evaluates the request against the associated Firewall Policy and application rules.
-
If the destination and protocol are permitted, Azure Firewall forwards the request to the external destination.
-
The response returns through Azure Firewall to the originating application, while diagnostic logs provide visibility into the connection.
Unlike transparent traffic interception, only applications configured to use the explicit proxy follow this path. Other traffic requires its own routing and security controls.
3. Prerequisites
Before configuring Azure Firewall Explicit Proxy, ensure that the following components are available.
|
Component |
Requirement |
|---|---|
|
Azure subscription |
Active subscription with deployment permissions |
|
Azure Firewall |
Standard or Premium |
|
Firewall Policy |
Associated with the firewall |
|
Virtual Network |
Deployed with workload connectivity |
|
Proxy-aware client |
Browser, application, or operating system supporting HTTP/HTTPS proxy |
|
Application rules |
Configured to allow the required destinations |
|
Azure Storage |
Optional, for PAC file hosting |
|
User-assigned managed identity |
Required for the documented managed identity-based PAC hosting configuration |
|
Azure CLI |
Installed and authenticated for CLI configuration |
You should also verify that the relevant Azure region, SKU, and subscription support the configuration you intend to deploy.
4. Configuring Azure Firewall Explicit Proxy
This section walks through enabling Explicit Proxy on an existing Azure Firewall using the Azure portal and Azure CLI.
Step 1: Open Azure Firewall Policy

-
Sign in to the Azure portal
-
Navigate to Firewall Manager or search for Firewall Policies.
-
Select the Firewall Policy associated with your Azure Firewall.
-
Open the Explicit Proxy configuration pane, where available.
Explicit Proxy is configured in the Firewall Policy rather than directly on the firewall resource.
Step 2: Enable Explicit Proxy
Enable Explicit Proxy and configure the proxy listener ports.
Example configuration
|
Setting |
Example value |
|---|---|
|
Enable Explicit Proxy |
Enabled |
|
HTTP port |
|
|
HTTPS proxy port |
|
|
Enable PAC file |
Optional |
|
PAC file port |
|
These are illustrative values. Confirm the exact supported port fields in your current Azure portal and API version.
Save the configuration and wait for the Firewall Policy update to complete.
Note that the explicit proxy listener uses the firewall’s private IP address. Clients must have network connectivity to that IP and port.
Step 3: Configure application rules
Application rules determine which outbound HTTP and HTTPS destinations are allowed through the firewall.
Navigate to the associated Firewall Policy and open Application Rules.
Create an application rule collection with the following example configuration:
|
Setting |
Example |
|---|
|
Rule collection name |
|
|
Priority |
|
|
Action |
Allow |
|
Rule name |
|
|
Source |
|
|
Protocol |
|
|
Destination |
|
Replace the sample source subnet and destination domains with those appropriate to your environment. Ensure the rule collection priority and any existing rules are consistent with your security policy.
For production deployments, use a destination allowlist rather than permitting unrestricted internet access.
Step 4: Configure Explicit Proxy using Azure CLI
You can also configure Explicit Proxy through Azure CLI.
First, authenticate and select the appropriate subscription:
az login az account set \ --subscription "<SUBSCRIPTION_ID>"
Set the deployment variables:
RESOURCE_GROUP="rg-network-prod" POLICY_NAME="afw-policy-prod"
Enable Explicit Proxy on the existing Firewall Policy:
az network firewall policy update \
--resource-group "$RESOURCE_GROUP" \
--name "$POLICY_NAME" \
--explicit-proxy \
enable-explicit-proxy=true \
http-port=8080 \
enable-pac-file=false
This is an illustrative CLI configuration based on the Microsoft Learn Explicit Proxy documentation. Verify the installed Azure CLI version and its supported parameters before running the command.
You can review the policy configuration with:
az network firewall policy show \ --resource-group "$RESOURCE_GROUP" \ --name "$POLICY_NAME" \ --output json
Confirm that Explicit Proxy is enabled and the configured port matches the client settings.
Step 5: Configure client proxy settings
Once the firewall policy is updated, configure the workload applications to use the firewall’s private IP address.
For example, assume:
-
Azure Firewall private IP:
10.0.1.4 -
HTTP proxy port:
8080
For Linux systems using environment variables:
export HTTP_PROXY="http://10.0.1.4:8080" export HTTPS_PROXY="http://10.0.1.4:8080" export NO_PROXY="localhost,127.0.0.1"
For a basic connectivity test:
curl -v \ --proxy http://10.0.1.4:8080 \ https://www.microsoft.com
The client sends HTTPS traffic using the HTTP proxy’s CONNECT method. The proxy URL scheme remains http:// in this example, even when the requested destination is HTTPS.
For Windows, you can configure the proxy in the operating system’s network proxy settings, through Group Policy, or within individual applications that support proxy configuration.
For Microsoft Edge, for example, proxy settings can be applied through supported operating system or enterprise policy configurations.
5. Configuring a PAC File (Optional)
A Proxy Auto-Configuration (PAC) file enables clients to select a proxy automatically based on the destination URL or hostname.
This is particularly useful in enterprise environments with multiple networks, internal services, and external SaaS applications.
Step 1: Create a PAC file
Create a file named proxy.pac with an example configuration:
function FindProxyForURL(url, host) {
// Bypass proxy for local resources
if (isPlainHostName(host) ||
shExpMatch(host, "*.internal.example.com")) {
return "DIRECT";
}
// Use Azure Firewall for external traffic
return "PROXY 10.0.1.4:8080; DIRECT";
}
This example sends matching external traffic through the proxy and specifies a direct fallback. In a security-sensitive deployment, consider removing DIRECT fallback for external destinations to prevent proxy bypass.
Step 2: Upload the PAC file to Azure Blob Storage

-
Create or select an Azure Storage account.
-
Create a blob container for PAC files.
-
Upload
proxy.pac. -
Configure access according to the supported PAC retrieval method.
Step 3: Configure managed identity
For the managed identity-based PAC configuration documented by Microsoft:
-
Create a user-assigned managed identity.
-
Assign the required
Storage Blob Data ContributorandStorage Blob Data Readerroles on the relevant storage account. -
Associate the identity with the Firewall Policy.
-
Configure the PAC file URL and enable PAC file hosting in Explicit Proxy.
Use the identity and PAC configuration flow supported by the current Azure portal or CLI version. Microsoft’s documentation has evolved over time, so verify the latest PAC retrieval and authorization requirements before deploying.
Step 4: Configure client PAC settings
Configure supported client applications to use the PAC file URL provided by the proxy configuration.
Test the PAC file from a client and confirm that it returns the expected proxy selection for internal and external destinations.
6. Security Best Practices
Azure Firewall Explicit Proxy can provide centralized outbound access control, but it should be deployed as part of a layered network security strategy.
-
Restrict access to the listener: Use subnet-level controls and network security policies to limit which workloads can connect to the proxy ports.
-
Use application allowlists: Permit only required FQDNs and protocols in application rules.
-
Prevent proxy bypass: Manage client settings centrally and restrict direct outbound connectivity where appropriate.
-
Use least privilege: Assign only the permissions required for firewall policy administration and PAC file retrieval.
-
Protect PAC configuration: Avoid exposing sensitive network details in PAC files and review access to the hosted configuration.
-
Enable diagnostic logging: Send relevant firewall logs to Log Analytics or another supported monitoring destination.
-
Use separate policies and subnets where appropriate: Segregate workload types to simplify policy enforcement and auditing.
-
Plan for failover: Ensure clients have an approved response if the proxy becomes unavailable rather than unintentionally bypassing security controls.
Important security consideration
Explicit Proxy is not a replacement for all network-layer security controls. It only applies to applications configured to use the proxy. Do not assume that all outbound traffic is automatically inspected or filtered by enabling this feature.
Also, Explicit Proxy does not provide TLS inspection. HTTPS proxying does not, by itself, decrypt the encrypted application payload for inspection.
7. Monitoring and Logging
Azure Firewall diagnostic logs provide visibility into proxied application traffic and policy decisions.
Configure diagnostic settings on Azure Firewall to send logs to a Log Analytics workspace, then use Azure Monitor to investigate traffic patterns and denied requests.
For example, the following Kusto Query Language (KQL) query can be used to explore application rule logs in the resource-specific AZFWApplicationRule table:
AZFWApplicationRule
| where TimeGenerated > ago(24h)
| project
TimeGenerated,
SourceIp,
Fqdn,
Action,
Protocol,
RuleCollection,
Rule
| order by TimeGenerated desc
The exact schema may vary depending on your diagnostic settings and logging configuration.
To investigate denied connections:
AZFWApplicationRule
| where TimeGenerated > ago(24h)
| where Action == "Deny"
| summarize DeniedRequests = count()
by SourceIp, Fqdn, Rule
| order by DeniedRequests desc
These queries help identify blocked destinations, investigate application misconfigurations, and review policy enforcement.
8. Troubleshooting Azure Firewall Explicit Proxy
|
Issue |
Possible cause |
Recommended action |
|---|---|---|
|
Connection timeout |
Network connectivity or incorrect proxy port |
Verify subnet routing, network controls, IP address, and listener port |
|
HTTP 403 or blocked request |
Application rule denies the destination |
Review rule collection priorities and FQDN allowlists |
|
HTTPS CONNECT failure |
Incorrect proxy configuration or destination rule |
Check the client proxy URL, CONNECT behavior, and HTTPS application rules |
|
PAC file not loading |
Invalid PAC URL, identity, or permissions |
Verify blob availability, identity role assignments, and PAC configuration |
|
Some applications bypass the proxy |
Application-specific proxy settings |
Configure supported client proxy policies and restrict direct egress |
|
No logs available |
Diagnostic settings not configured |
Enable application rule diagnostics and verify the Log Analytics destination |
|
DNS-related errors |
Incorrect name resolution or destination configuration |
Verify DNS resolution and destination FQDN requirements |
For basic testing, use:
curl -v \ --proxy http://10.0.1.4:8080 \ https://www.microsoft.com
Then inspect the corresponding firewall application rule logs to confirm whether the connection was allowed or denied.
Microsoft’s documentation also provides configuration guidance and troubleshooting details for explicit proxy scenarios.Azure Firewall Explicit Proxy documentation
9. Enterprise Deployment Considerations
For larger Azure environments, Explicit Proxy can be incorporated into a centralized outbound security architecture.
Recommended enterprise design
-
Deploy Azure Firewall in a dedicated hub VNet and connect workload VNets through VNet peering or a supported hub-and-spoke design.
-
Configure explicit proxy settings consistently across proxy-aware workloads using approved endpoint management mechanisms.
-
Use Firewall Policy inheritance and rule collections to support centralized governance.
-
Maintain separate outbound security controls for non-proxy-aware applications and other protocols.
-
Use Azure Monitor and Log Analytics to support centralized audit and operational monitoring.
For hybrid environments, on-premises servers can also use Azure Firewall Explicit Proxy when appropriate private connectivity, such as ExpressRoute or site-to-site VPN, is available. Azure Arc scenarios have additional configuration requirements and documented limitations.
10. Azure Firewall Explicit Proxy vs. Traditional Proxy Solutions
|
Capability |
Azure Firewall Explicit Proxy |
Traditional dedicated forward proxy |
|---|---|---|
|
Azure-native integration |
Yes |
Depends on vendor |
|
HTTP/HTTPS proxy |
Yes |
Commonly supported |
|
Application rules |
Azure Firewall Policy |
Vendor-specific policies |
|
Centralized Azure governance |
Azure Policy and Firewall Policy |
Depends on integration |
|
PAC file support |
Yes |
Commonly supported |
|
TLS inspection |
Not supported by Explicit Proxy |
Depends on product |
|
Azure Monitor integration |
Supported |
Depends on connector |
|
Infrastructure management |
Azure-managed service |
Often requires separate management |
|
Non-HTTP/HTTPS traffic |
Requires other firewall controls |
Depends on product |
The choice depends on the organization’s existing security architecture, inspection requirements, application compatibility, operational model, and cost considerations. Explicit Proxy is a forward-proxy capability, not a complete substitute for dedicated secure web gateways where advanced web inspection or user-level controls are required.
11. Conclusion
Azure Firewall Explicit Proxy provides an application-aware way to control outbound HTTP and HTTPS traffic in Azure environments. By configuring proxy-aware clients to use the firewall’s private IP address, organizations can apply centralized application rules, manage destination access, and monitor permitted and denied connections.
Its integration with Firewall Policy, optional PAC file configuration, and Azure Monitor can help simplify outbound security management for suitable workloads.
Successful deployment depends on correct client configuration, carefully scoped application rules, appropriate controls for direct outbound traffic, and ongoing monitoring. Organizations should validate the feature against their specific Azure environment and current Microsoft documentation before adopting it for production workloads.