Umbraco 17 behind Azure Front Door - Not Publishing changes

Hi all,

We have a site set up behind Azure Front Door. The application is split between the frontend and backend. When accessing the backend via the Front Door URL, we are unable to publish any changes to pages. I can’t see anything in the log that I wouldn’t expect, but I’m seeing a 403 in the network inspection in FireFox dev tools.

Any pointers of where to go?

Hi @marshdenyerprocentia

Welcome to the forum!

My first guess would be the WAF on Front Door. Saving and publishing sends JSON with HTML in it (rich text, block content etc.) and that often trips the managed XSS/SQL injection rules. Front Door blocks it with a 403 before it gets to Umbraco, which is why you’re not seeing anything in the logs.

If you look at the response body of the 403 it’ll probably be Front Door’s “request is blocked” page, and there should be an x-azure-ref header. If you’ve got diagnostics going to Log Analytics you can search the WAF logs for that to see which rule fired. A quick way to confirm is to switch the WAF policy to Detection mode and try publishing again.

I wouldn’t exclude the whole of /umbraco though, as that also covers surface controller posts, the Delivery API and the login. If your editors work from known IPs, the best option is a custom rule that only allows /umbraco/management/api/ and /umbraco/backoffice from those IPs. Otherwise either scope an Allow rule to just /umbraco/management/api/, or exclude the specific rules that are firing.

Also worth making sure caching is turned off on the route for /umbraco/* if it isn’t already.

Justin (with some help from AI)