Azure Application Gateway: export inventory

Overview

This PowerShell script searches all enabled Azure subscriptions available to the current account, inventories every Azure Application Gateway, and exports the results to CSV files.

It captures:

  • Gateway and frontend IP details.
  • HTTP listener definitions.
  • Backend address pools.
  • Request routing rules.

This is useful when you need to quickly identify:

  • Which subscriptions and resource groups contain each Application Gateway.
  • Which VNets and subnets host each gateway.
  • Which public and private frontend IPs are configured.
  • Which listeners, backend pools, and routing rules are defined.

What the script does

  • Retrieves enabled subscriptions with Get-AzSubscription.
  • Switches context into each subscription with Set-AzContext.
  • Reads Application Gateways with Get-AzApplicationGateway.
  • Extracts gateway subnet and VNet information from gateway IP configurations.
  • Resolves associated public IP addresses with Get-AzPublicIpAddress.
  • Flattens listeners, backend pools, and routing rules into separate CSV exports.
  • Prints progress to the console while collecting results.

Prerequisites

Install the Azure PowerShell modules if needed:

Install-Module Az -Scope CurrentUser

Connect to Azure before running the script:

Connect-AzAccount

The account must have permission to read Application Gateways and public IP addresses in the subscriptions being checked.

Output

The CSV files are written under:

.\appgw-export

Generated files:

  • appgw-gateways.csv
  • appgw-listeners.csv
  • appgw-backends.csv
  • appgw-routing-rules.csv

Gateways CSV columns

  • SubscriptionName
  • SubscriptionId
  • ResourceGroup
  • GatewayName
  • Location
  • VNetName
  • SubnetName
  • SubnetId
  • FrontendName
  • FrontendPrivateIP
  • PublicIPName
  • PublicIPAddress
  • PublicIPFQDN
  • SkuName
  • SkuTier
  • EnableHttp2

Listeners CSV columns

  • SubscriptionName
  • SubscriptionId
  • ResourceGroup
  • GatewayName
  • ListenerName
  • FrontendName
  • Protocol
  • Port
  • HostNames
  • SslCertificate

Backends CSV columns

  • SubscriptionName
  • SubscriptionId
  • ResourceGroup
  • GatewayName
  • BackendPoolName
  • BackendAddresses

Routing rules CSV columns

  • SubscriptionName
  • SubscriptionId
  • ResourceGroup
  • GatewayName
  • RuleName
  • RuleType
  • Priority
  • ListenerName
  • BackendPool
  • BackendSettings
  • RedirectConfig
  • UrlPathMap

PowerShell script

$OutputFolder = ".\appgw-export"
 
New-Item -ItemType Directory -Path $OutputFolder -Force | Out-Null
 
$gateways   = @()
$listeners  = @()
$backends   = @()
$rules      = @()
 
$subscriptions = Get-AzSubscription |
    Where-Object { $_.State -eq "Enabled" }
 
foreach ($subscription in $subscriptions) {
 
    Write-Host ""
    Write-Host "=== $($subscription.Name) ===" -ForegroundColor Yellow
 
    Set-AzContext -SubscriptionId $subscription.Id | Out-Null
 
    $appGateways = Get-AzApplicationGateway -ErrorAction SilentlyContinue
 
    foreach ($gw in $appGateways) {
 
        Write-Host "Processing App Gateway: $($gw.Name)" -ForegroundColor Cyan
 
        # Gateway subnet(s)
        $subnetIds = @(
            $gw.GatewayIPConfigurations |
            ForEach-Object { $_.Subnet.Id } |
            Where-Object { $_ } |
            Select-Object -Unique
        )
 
        $subnetNames = @(
            $subnetIds |
            ForEach-Object { ($_ -split "/")[-1] }
        )
 
        $vnetNames = @(
            $subnetIds |
            ForEach-Object {
                $parts = $_ -split "/"
                $vnetIndex = [Array]::IndexOf($parts, "virtualNetworks")
                if ($vnetIndex -ge 0) {
                    $parts[$vnetIndex + 1]
                }
            } |
            Where-Object { $_ } |
            Select-Object -Unique
        )
 
        # Frontend IPs
        foreach ($frontend in $gw.FrontendIPConfigurations) {
 
            $publicIpName = ""
            $publicIpAddress = ""
            $publicIpDns = ""
 
            if ($frontend.PublicIPAddress.Id) {
 
                $publicIpName = ($frontend.PublicIPAddress.Id -split "/")[-1]
 
                try {
                    $pip = Get-AzPublicIpAddress `
                        -ResourceGroupName $gw.ResourceGroupName `
                        -Name $publicIpName `
                        -ErrorAction Stop
 
                    $publicIpAddress = $pip.IpAddress
                    $publicIpDns = $pip.DnsSettings.Fqdn
                }
                catch {}
            }
 
            $gateways += [PSCustomObject]@{
                SubscriptionName    = $subscription.Name
                SubscriptionId      = $subscription.Id
                ResourceGroup       = $gw.ResourceGroupName
                GatewayName         = $gw.Name
                Location            = $gw.Location
 
                VNetName            = ($vnetNames -join ", ")
                SubnetName          = ($subnetNames -join ", ")
                SubnetId            = ($subnetIds -join ", ")
 
                FrontendName        = $frontend.Name
                FrontendPrivateIP   = $frontend.PrivateIPAddress
 
                PublicIPName        = $publicIpName
                PublicIPAddress     = $publicIpAddress
                PublicIPFQDN        = $publicIpDns
 
                SkuName             = $gw.Sku.Name
                SkuTier             = $gw.Sku.Tier
                EnableHttp2         = $gw.EnableHttp2
            }
        }
 
        # Listeners
        foreach ($listener in $gw.HttpListeners) {
 
            $frontendName = ""
            $frontendPort = ""
 
            if ($listener.FrontendIPConfiguration.Id) {
                $frontendName = ($listener.FrontendIPConfiguration.Id -split "/")[-1]
            }
 
            if ($listener.FrontendPort.Id) {
 
                $portName = ($listener.FrontendPort.Id -split "/")[-1]
 
                $portObject = $gw.FrontendPorts |
                    Where-Object { $_.Name -eq $portName }
 
                $frontendPort = $portObject.Port
            }
 
            $hostNames = @()
 
            if ($listener.HostName) {
                $hostNames += $listener.HostName
            }
 
            if ($listener.HostNames) {
                $hostNames += $listener.HostNames
            }
 
            $listeners += [PSCustomObject]@{
                SubscriptionName = $subscription.Name
                SubscriptionId   = $subscription.Id
                ResourceGroup    = $gw.ResourceGroupName
                GatewayName      = $gw.Name
 
                ListenerName     = $listener.Name
                FrontendName     = $frontendName
                Protocol         = $listener.Protocol
                Port             = $frontendPort
                HostNames        = (($hostNames | Where-Object { $_ } | Select-Object -Unique) -join ", ")
 
                SslCertificate   = if ($listener.SslCertificate.Id) {
                    ($listener.SslCertificate.Id -split "/")[-1]
                } else { "" }
            }
        }
 
        # Backend pools
        foreach ($pool in $gw.BackendAddressPools) {
 
            $addresses = @()
 
            foreach ($address in $pool.BackendAddresses) {
 
                if ($address.IpAddress) {
                    $addresses += $address.IpAddress
                }
 
                if ($address.Fqdn) {
                    $addresses += $address.Fqdn
                }
            }
 
            $backends += [PSCustomObject]@{
                SubscriptionName = $subscription.Name
                SubscriptionId   = $subscription.Id
                ResourceGroup    = $gw.ResourceGroupName
                GatewayName      = $gw.Name
 
                BackendPoolName  = $pool.Name
                BackendAddresses = ($addresses -join ", ")
            }
        }
 
        # Request routing rules
        foreach ($rule in $gw.RequestRoutingRules) {
 
            $rules += [PSCustomObject]@{
                SubscriptionName = $subscription.Name
                SubscriptionId   = $subscription.Id
                ResourceGroup    = $gw.ResourceGroupName
                GatewayName      = $gw.Name
 
                RuleName         = $rule.Name
                RuleType         = $rule.RuleType
                Priority         = $rule.Priority
 
                ListenerName     = if ($rule.HttpListener.Id) {
                    ($rule.HttpListener.Id -split "/")[-1]
                } else { "" }
 
                BackendPool      = if ($rule.BackendAddressPool.Id) {
                    ($rule.BackendAddressPool.Id -split "/")[-1]
                } else { "" }
 
                BackendSettings  = if ($rule.BackendHttpSettings.Id) {
                    ($rule.BackendHttpSettings.Id -split "/")[-1]
                } else { "" }
 
                RedirectConfig   = if ($rule.RedirectConfiguration.Id) {
                    ($rule.RedirectConfiguration.Id -split "/")[-1]
                } else { "" }
 
                UrlPathMap       = if ($rule.UrlPathMap.Id) {
                    ($rule.UrlPathMap.Id -split "/")[-1]
                } else { "" }
            }
        }
    }
}
 
$gateways |
    Export-Csv "$OutputFolder\appgw-gateways.csv" `
    -NoTypeInformation -Encoding UTF8
 
$listeners |
    Export-Csv "$OutputFolder\appgw-listeners.csv" `
    -NoTypeInformation -Encoding UTF8
 
$backends |
    Export-Csv "$OutputFolder\appgw-backends.csv" `
    -NoTypeInformation -Encoding UTF8
 
$rules |
    Export-Csv "$OutputFolder\appgw-routing-rules.csv" `
    -NoTypeInformation -Encoding UTF8
 
Write-Host ""
Write-Host "Application Gateway export complete: $OutputFolder" -ForegroundColor Green