{Network} az network firewall policy: Expose read-only afcManaged property and bump API version to 2025-09-01 - #10409
Merged
Ethan Yang (necusjz) merged 2 commits intoOct 1, 2026
Conversation
microsoft-github-policy-service
Bot
requested review from
Yu Chen (jsntcy),
Ethan Yang (necusjz) and
Yong Zhang (yonzhan)
September 30, 2026 05:40
…ings to 2025-09-01 These 9 recording files were unrelated to the afcManaged/policy change but failed CI (CannotOverwriteExistingCassetteException) because azure-cli core's network public-ip create/show commands now default to api-version=2025-09-01 while the cassettes were recorded against 2024-07-01. Only blocks whose CommandName is 'network public-ip *' were updated; unrelated blocks (e.g. subnet/vnet show, still on 2024-07-01 upstream) were left untouched.
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The regenerated update command introduces a misspelled IDPS argument group that splits related options in help output.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Updates Azure Firewall Policy commands to API 2025-09-01, exposing the read-only afcManaged property requested by Azure/azure-cli#33903.
Changes:
- Regenerates policy operations and schemas for the new API.
- Preserves existing identity and IDPS command interfaces.
- Adds validation, recordings, release history, and version
2.3.0.
| File | Description |
|---|---|
src/azure-firewall/setup.py |
Bumps the extension version. |
src/azure-firewall/HISTORY.rst |
Documents the API and output changes. |
src/azure-firewall/azext_firewall/tests/latest/test_azure_firewall_scenario.py |
Verifies afcManaged output. |
.../recordings/test_firewall_vhub_create_with_public_ip.yaml |
Refreshes public-IP API requests. |
.../recordings/test_firewall_basic_sku.yaml |
Refreshes public-IP API requests. |
.../recordings/test_azure_policy_rcg_draft.yaml |
Updates parent policy requests. |
.../recordings/test_azure_firewall_with_firewall_policy_premium.yaml |
Updates policy requests. |
.../recordings/test_azure_firewall_policy_rules_with_fqdns.yaml |
Updates policy requests. |
.../recordings/test_azure_firewall_extended_location.yaml |
Refreshes public-IP API requests. |
.../recordings/test_azure_firewall_autoscale_configuration.yaml |
Refreshes public-IP API requests. |
src/azure-firewall/azext_firewall/custom.py |
Hides duplicate generated identity arguments. |
.../policy/_wait.py |
Updates wait schema and API version. |
.../policy/_update.py |
Updates policy read/write schemas and API version. |
.../policy/_show.py |
Exposes afcManaged in show output. |
.../policy/_list.py |
Updates list operations and response schemas. |
.../policy/_delete.py |
Updates delete to the new API. |
.../policy/_create.py |
Updates create schema, identity handling, and API version. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Collaborator
|
Network |
Ethan Yang (necusjz)
approved these changes
Oct 1, 2026
Collaborator
|
[Release] Update index.json for extension [ azure-firewall-2.3.0 ] : https://dev.azure.com/msazure/One/_build/results?buildId=183638995&view=results |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Related command
az network firewall policy show / create / update / list / delete / waitGeneral Guidelines
azdev style <YOUR_EXT>locally? (pip install azdevrequired)python scripts/ci/test_index.py -qlocally? (pip install azdevrequired)For new extensions:
About Extension Publish
There is a pipeline to automatically build, upload and publish extension wheels.
Once your pull request is merged into main branch, a new pull request will be created to update
src/index.jsonautomatically.You only need to update the version information in file setup.py and historical information in file HISTORY.rst in your PR but do not modify
src/index.json.Description
Fixes Azure/azure-cli#33903
AAZ Azure/aaz#1108
Microsoft.Network/firewallPoliciesnow returns a read-onlyafcManagedboolean property indicating whether a firewall policy is managed by Azure Firewall Configuration (AFC) (see swagger PR Azure/azure-rest-api-specs#44867, minimum API version2025-09-01). This PR:az network firewall policycreate/update/show/list/delete/wait(andintrusion-detection add/remove, which reuse the same underlying resource operations) from2022-01-01to2025-09-01.afcManagedas a read-only property in the command output (mainly visible viaaz network firewall policy show). No new write parameter (--afc-managed) is added, since the property is read-only in the swagger.afcManagedSync, since it is intended for the AFC service to write managed policies, not for general CLI users.policynode so they don't leak into this PR:--idps-profileargument name oncreate/update(regenerator had renamed it to--profile).--system-assigned/--user-assignedidentity args oncreateto avoid duplicating the existing custom--identityargument.network firewall policy deployandrule-collection-group[/draft] collectioncommand groups whose API version was not part of this change.Testing Guide
Scenario tests updated/verified:
test_azure_firewall_policy(addedself.check('afcManaged', False)assertion onshowoutput)test_azure_policy_idps_profilestest_azure_firewall_policy_intrusion_detectiontest_azure_firewall_policy_app_rules_with_custom_headersVCR recordings for the affected commands were updated to
api-version=2025-09-01.History Notes
[Network]
az network firewall policy show: Add read-onlyafcManagedproperty indicating whether the policy is managed by Azure Firewall Configuration (AFC){Network}
az network firewall policy: Bump API version to2025-09-01forcreate/update/show/list/delete/wait