AWS Shield Advanced Retires L7 Auto-Mitigation, Shifts to WAF Managed Rule Group
AWS is phasing out its Shield Advanced Layer 7 automatic mitigation feature, transitioning customers to a new Anti-DDoS managed rule group within AWS WAF by January 1, 2027.

Amazon Web Services (AWS) is set to retire its Shield Advanced Layer 7 (L7) automatic mitigation feature, a core component of its managed DDoS protection service. The change, scheduled to take full effect on January 1, 2027, will see AWS Shield Advanced customers migrate to a new Anti-DDoS managed rule group integrated directly into AWS Web Application Firewall (WAF) access control lists (ACLs). This strategic shift aims to provide enhanced and more flexible application-layer DDoS protection.
The new Anti-DDoS managed rule group is designed to preserve traffic flow and operate in conjunction with existing AWS WAF rules and other mitigation strategies. It will be automatically added to eligible Shield Advanced web ACLs in a 'Count' mode between July 27 and August 7, 2026, allowing customers a transition period to evaluate its performance. AWS is encouraging customers to review the new dashboard within the AWS WAF console, compare key metrics like DDoSDetected and DDoSAttackRequests to validate detection accuracy, and leverage AWS WAF labels for detailed analysis of suspicious traffic patterns.
During this evaluation phase, AWS recommends starting with a 'Low' sensitivity setting for Block actions and adjusting based on observed data and labels. Customers will also need to configure URI exemptions for any unsupported paths and update their infrastructure-as-code (IaC) templates to reflect the changes. The migration process is being rolled out in five phases, with existing automatic mitigation remaining active until the new rule group fully assumes protection responsibilities.
Upon its full implementation, the Anti-DDoS managed rule group will offer several key capabilities. It learns normal traffic patterns, responds dynamically to attacks, and operates independently of health checks. The rule group introduces a 'Challenge' action alongside 'Block' and 'Count', supporting silent browser verification. Sensitivity for both Block and Challenge actions can be configured independently, with options for unsupported paths to fall back to 'Block' mode. This update also significantly reduces the web ACL capacity requirement from 150 to 50 Web Capacity Units (WCUs).
Monitoring and visibility are enhanced with new Amazon CloudWatch metrics, including DDoSAttackRequests for application-layer attacks, complementing existing L3/L4 DDoSDetected metrics. Every inspected request will be labeled, providing detailed insights into detected events, suspicion levels, and mitigation decisions. These labels can be used in custom AWS WAF rules, CloudWatch dashboards, and log analysis tools like Amazon Athena. Blocked DDoS requests during active mitigation will be excluded from AWS WAF and Shield Advanced request charges, offering cost benefits.
AWS Firewall Manager users will need to update their policies to include the AWSManagedRulesAntiDDoSRuleSet, as application-layer protection is moving from Shield Advanced policies to AWS WAF. Organizations utilizing IaC tools such as CloudFormation, CDK, or Terraform must update their templates to replace existing Shield automatic mitigation settings with the new managed rule group. After AWS applies the automatic upgrade, teams should import the updated web ACL into their IaC tooling to prevent accidental reversion.
AWS Shield Advanced subscribers will receive the new rule group at no additional cost, included with their WAF subscription, and it can also be enabled independently by any AWS WAF customer. Pricing considerations include a generous request limit of up to 50 billion per month for Shield Advanced subscribers. During active mitigation in Block or Challenge mode, traffic that is blocked is not subject to AWS WAF, rule group, or Shield Advanced request charges. Web ACLs updated automatically between July 27 and September 30, 2026, will also benefit from a waiver on per-request fees and WCU consumption during their evaluation period, even when operating in Count mode.