As part of our ongoing commitment to elevate securing Power Pages, we’re excited to announce the release of Azure managed Bot Protection rule designed to help safeguard sites against automated threats like credential stuffing, spam, and scraping attacks.
Bot Protection Rule
The Bot Protection rule adds a layer of defense by identifying and blocking suspicious, bot-like activity in real time before it can impact sites. Bots can be helpful (like search engine crawlers) or harmful (like scrapers, spam bots, and credential stuffing tools). Power Pages allows configuring rules that distinguish between:
Good Bots – Legitimate crawlers like Bing or other search engines like Google.
Bad Bots – Malicious bots designed to steal data or disrupt services.
Unknown Bots – Bots that don’t identify themselves clearly.
Enhanced Control Over Managed Rules
While managed rules have already existed behind the scenes, now makers can easily enable or disable specific managed rules directly from the Security workspace in Pages Design Studio. This gives better visibility and control over the protection applied to site. The managed rules categories include Cross-site scripting, Session fixation attack, Local and Remote file attack, etc. Using the configuration interface, specific subset rules within these categories can be enabled or disabled.
Learn more about configuring the feature by visiting documentation.
We are looking forward to your feedback
Your feedback is crucial in shaping the future of this feature. We want to hear from you!
The post Enhance Power Pages site security with Bot Protection and Managed Rules configuration appeared first on Microsoft Power Platform Blog.
Source: Microsoft Power Platform