{"@odata.context":"https://relcomms-prod-dagnegedescbeefs.b02.azurefd.net/api/v2/$metadata#Azure/$entity","id":"497535","productCategories":["Networking"],"tags":["Features","Services"],"products":["Azure DNS"],"generalAvailabilityDate":"2025-07","previewAvailabilityDate":null,"privatePreviewAvailabilityDate":null,"title":"Generally Available: Azure DNS security policy","description":"<p style=\"margin:0in 0in 8pt;font-size:12pt;font-family:Aptos, sans-serif;margin-bottom:0in\">DNS security policy is now\ngenerally available. This release brings visibility of DNS traffic at the VNET\nlevel with the flexibility to send logs to storage account, log analytics\nworkspace, or event hubs. It also includes DNS filtering based on lists of\ndomains for allow/block actions.&nbsp; &nbsp;&nbsp;</p><p style=\"margin:0in 0in 8pt;font-size:12pt;font-family:Aptos, sans-serif;margin-bottom:0in\">&nbsp;</p><p style=\"margin:0in 0in 8pt;font-size:12pt;font-family:Aptos, sans-serif;margin-bottom:0in\">What DNS security policy?&nbsp;&nbsp;&nbsp;</p><p style=\"margin:0in 0in 8pt;font-size:12pt;font-family:Aptos, sans-serif;margin-bottom:0in\">DNS security policy offers the\nability to filter DNS queries on VNETs. You can allow, alert, or block name\nresolution of known or malicious domains and gain insight into your DNS\ntraffic. Detailed DNS logs can be sent to a storage account, log analytics workspace,\nor event hubs.&nbsp;&nbsp;&nbsp;</p><p style=\"margin:0in 0in 8pt;font-size:12pt;font-family:Aptos, sans-serif;margin-bottom:0in\">&nbsp;</p><p style=\"margin:0in 0in 8pt;font-size:12pt;font-family:Aptos, sans-serif;margin-bottom:0in\">A DNS security policy has the\nfollowing elements:&nbsp;&nbsp;&nbsp;</p><ul><li>Location: A security policy can only apply to\nVNets in the same region.&nbsp;&nbsp;&nbsp;</li><li>DNS traffic rules: Rules that allow/block/alert\nqueries based on priority and domain lists.&nbsp;&nbsp;</li><li>VNET links: A security policy can be associated\nto multiple VNets.&nbsp;&nbsp;&nbsp;</li><li>DNS domain lists: Location-based lists of DNS\ndomains.&nbsp;&nbsp;&nbsp;</li></ul><p style=\"margin:0in 0in 8pt;font-size:12pt;font-family:Aptos, sans-serif;margin-bottom:0in\">&nbsp;</p><p style=\"margin:0in 0in 8pt;font-size:12pt;font-family:Aptos, sans-serif;margin-bottom:0in\">Key benefits:&nbsp;&nbsp;&nbsp;</p><ul><li>Visibility of DNS traffic: DNS security policy\nbrings the ability of logging your DNS traffic at the virtual network\nlevel.&nbsp;&nbsp;&nbsp;</li><li>DNS traffic filtering: Allows to create DNS\ntraffic rules which can contain multiple domain lists which can be used to\nallow/block DNS traffic.&nbsp;&nbsp;&nbsp;</li></ul><p style=\"margin:0in 0in 8pt;font-size:12pt;font-family:Aptos, sans-serif;margin-bottom:0in\"><a style=\"text-decoration: underline; color: rgb(70, 120, 134);\" href=\"https://learn.microsoft.com/en-us/azure/dns/dns-security-policy\">Learn\nmore</a>. &nbsp;</p>","status":"Launched","created":"2025-07-02T18:00:55.7106645Z","modified":"2025-07-02T18:00:55.7106645Z","locale":null,"availabilities":[{"ring":"General Availability","year":2025,"month":"July"}]}