Generated on: December 10, 2025 Target period: Within the last 24 hours Processing mode: Details Mode Number of updates: 1 items
Published: December 09, 2025 13:15:11 UTC Link: Generally Available: FIPS compliant mode for Application Gateway V2 SKUs
Update ID: 536712 Data source: Azure Updates API
Categories: Launched, Networking, Security, Application Gateway
Summary:
What was updated
Azure Application Gateway V2 SKUs now support a FIPS 140-2 compliant mode.
Key changes or new features
The update enables Application Gateway V2 to operate in a FIPS 140-2 validated cryptographic mode, meeting US government standards for cryptographic modules. This ensures that all cryptographic operations within the gateway adhere to strict security requirements, enhancing compliance and security posture for regulated environments.
Target audience affected
Developers and IT professionals managing secure Azure network infrastructure, especially those in government, defense, finance, or other regulated industries requiring FIPS compliance.
Important notes if any
Enabling FIPS mode may impact performance due to the use of FIPS-validated cryptographic modules. Users should validate compatibility with their applications and workloads before enabling this mode. This feature is generally available and can be configured on existing Application Gateway V2 deployments.
Details:
The recent Azure update announces the general availability of FIPS 140-2 compliant mode for Application Gateway V2 SKUs, enhancing cryptographic security to meet stringent US government standards. FIPS 140-2 is a federal standard that specifies security requirements for cryptographic modules used within IT products, ensuring data protection and compliance in regulated environments. By enabling FIPS mode, Azure Application Gateway V2 now supports cryptographic operations validated against these standards, making it suitable for workloads requiring high-assurance security.
Background and Purpose:
This update addresses the need for organizations, especially those in government, defense, finance, and healthcare sectors, to comply with federal security mandates. Application Gateway is a Layer 7 load balancer and web application firewall (WAF) service that manages inbound web traffic. Prior to this update, customers requiring FIPS 140-2 compliance had to implement additional controls or use other services. The introduction of FIPS mode directly within Application Gateway V2 simplifies compliance and reduces operational overhead.
Specific Features and Changes:
Technical Mechanisms and Implementation:
The FIPS mode leverages cryptographic libraries that have been validated against FIPS 140-2 standards. When enabled, the Application Gateway enforces the use of FIPS-approved algorithms such as AES for encryption, SHA-2 for hashing, and RSA or ECDSA for key exchange and digital signatures. TLS protocols and cipher suites are restricted to those compliant with FIPS, disabling weaker or non-validated algorithms. Configuration is typically done through Azure CLI, PowerShell, or ARM templates by setting the enableFips flag to true on the Application Gateway resource. Internally, the gateway’s SSL termination process uses FIPS-certified cryptographic modules, ensuring end-to-end compliance.
Use Cases and Application Scenarios:
Important Considerations and Limitations:
Integration with Related Azure Services:
In summary, the general availability of FIPS 140-2 compliant mode for Azure Application Gateway V2
This report was automatically generated - 2025-12-10 03:01:18 UTC