Disabled WAF keeps applications in Azure Application Gateway open to all layer 7 attacks.
In Azure Console -
In Terraform -
References:
https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/ag-overview
https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/application_gateway#waf_configuration