Skip to content
Search Sign in List your company

Azure Front Door

by Microsoft Azure from Microsoft

Page last updated
25 August 2026
What these mean

Report a problem with this product

Price on request

Azure Front Door is Microsoft Azure's global application delivery and cloud CDN service for accelerating and protecting internet-facing websites, APIs and applications with edge routing, caching, load balancing and security controls.

About Azure Front Door

Azure Front Door is Microsoft Azure's global application delivery and cloud CDN service for internet-facing websites, APIs and applications. It uses Microsoft's global edge network to route users to healthy origins, accelerate static and dynamic content, cache eligible responses, terminate TLS at the edge and apply security controls before requests reach application backends. Front Door is offered in Standard and Premium tiers. Standard emphasizes content delivery and acceleration, while Premium adds stronger security and private-origin capabilities. Buyers should evaluate traffic geography, origin architecture, security requirements and data-transfer patterns because the service combines fixed profile fees with request and bandwidth charges.

What is included

Delivery

Global CDN and routing Uses Microsoft's global edge network for static and dynamic content delivery, global routing and origin health-based traffic distribution.

Tiers

Standard and Premium Standard is content-delivery optimized; Premium adds stronger security features and Azure Private Link support for supported origins.

Security

Web Application Firewall Supports Azure WAF at the edge; Premium includes managed WAF rule sets, bot protection and Microsoft Threat Intelligence integration.

Networking

Private Link Premium can connect privately to supported Azure origins so backend services do not need direct public exposure.

Caching

Edge caching Can cache eligible content at edge points of presence and accelerate uncached requests through Microsoft's global network.

Availability

Health-based routing Origin groups, health probes, priorities and weights support multi-origin and multi-region application delivery patterns.

Pricing

Profile and usage billing Current US pricing includes a base profile fee plus request and data-transfer meters, with rates varying by tier, geography and usage.

Lifecycle

Classic retirement Azure Front Door Classic retires March 31, 2027; Microsoft directs customers to migrate to Standard or Premium.

What is Azure Front Door used for?

Azure Front Door is used as a global entry point for public web applications, APIs and content. It can route users to origins in different regions based on health and routing configuration, cache content at Microsoft's edge locations, accelerate dynamic requests through the Microsoft network and manage custom domains and TLS certificates. Common scenarios include global websites, ecommerce platforms, SaaS applications, API endpoints, media delivery and multi-region applications that need one public endpoint.

Front Door does not host the application itself. Origins can include services such as Azure App Service, Azure Storage, load-balanced applications and supported custom endpoints. That makes Front Door complementary to App Service, AKS, Container Apps and Virtual Machines rather than a replacement for those runtimes.

How do Standard and Premium tiers differ?

Microsoft currently offers Azure Front Door Standard and Premium. Standard is content-delivery optimized and includes static and dynamic acceleration, global load balancing, SSL offload, domain and certificate management, traffic analytics and basic security capabilities. Premium builds on Standard and adds more security-focused capabilities, including managed Web Application Firewall rule sets, bot protection, integration with Microsoft Threat Intelligence, security analytics and Azure Private Link support for supported origins.

The choice should be driven by origin exposure and security requirements, not only traffic volume. A public application that mainly needs global routing and caching may fit Standard. An application that needs private origin connectivity or the full Premium security set should evaluate Premium.

How do routing, origins and health probes work?

Front Door routes incoming requests through endpoints, routes and origin groups. An origin group can contain several application backends, and health probes help Front Door determine which origins are available. Routing can use priority and weight so teams can build active-active or active-standby patterns across application instances or regions.

This improves application availability only when the origins themselves are designed for failover. A Front Door profile cannot make a single unhealthy backend highly available. Teams should deploy resilient origins, use appropriate data replication and test failures so traffic switching does not expose application or database dependencies that remain tied to one region.

What caching and edge acceleration capabilities are included?

Azure Front Door can cache eligible static and dynamic responses at edge points of presence and can accelerate uncached traffic by carrying requests across Microsoft's global network. The platform also supports response compression, custom domains, managed certificates and a rules engine for request and response handling.

Caching needs application-aware configuration. Personalized or private responses should not be cached accidentally, while query-string behavior, cache-control headers and purge procedures need to match the application's content model. Teams should measure cache hit rates and origin traffic because poor cache configuration can reduce the performance and cost benefits expected from a CDN.

How does Azure Front Door pricing work?

Azure Front Door does not have one fixed monthly product price. Microsoft's current US pricing page lists a base fee of $35 per month for Standard and $330 per month for Premium, calculated from hourly usage. Additional billing dimensions include outbound data transfer from the edge to clients, data transfer from the edge to origins and incoming requests at Front Door edge locations. Rates vary by geographic pricing zone and usage volume.

Premium includes managed WAF and Private Link pricing in the Premium tier, while larger events such as data transfer and request volume can still dominate the final bill. Pricing was checked on August 26, 2026. Buyers should model the actual mix of requests, cache hit ratio, response size, origin traffic, geographic distribution and security tier rather than comparing only the base fee.

What security controls should buyers plan for?

Microsoft recommends protecting internet-facing applications with appropriate DDoS and web application firewall controls. Front Door provides platform-level network DDoS protection and can inspect application traffic through Azure Web Application Firewall. Premium adds managed WAF rule sets, bot protection and Microsoft Threat Intelligence integration. Premium can also connect privately to supported Azure origins through Private Link so the backend does not need to be directly reachable from the public internet.

Security still depends on configuration. Origins should be restricted so attackers cannot bypass Front Door and call the backend directly. Microsoft documents options such as Private Link, managed identity origin authentication, service-tag filtering and Front Door header validation depending on the origin type.

What limits and operational issues should teams consider?

Azure Front Door has service limits that matter for large or heavily customized deployments. Microsoft currently documents a composite route limit of 5,000 per Front Door profile. Private Link traffic also has regional-cluster limits, so very high request rates may require multiple origin and Private Link region designs. Features and quotas should be checked against the exact architecture before consolidating many domains and routes into one profile.

Configuration changes can also take several minutes to propagate across edge locations. Teams should monitor origin health, request logs, WAF activity, cache behavior and certificate status rather than treating the edge service as a set-and-forget component.

What does the Azure Front Door Classic retirement mean?

Azure Front Door Classic is a legacy tier and should not be selected for a new design. Microsoft states that Front Door Classic retires on March 31, 2027. It no longer supports new profile creation, new domain onboarding or managed certificates, and Microsoft directs customers to migrate to Front Door Standard or Premium.

Existing Classic customers should plan migration rather than extending the legacy architecture. Microsoft provides migration tooling and states that the migration can be performed without traffic downtime because it is primarily a control-plane transition. Teams should still test configuration differences, certificate validation and automation changes before the retirement deadline.

Who should choose something else?

Teams serving traffic only inside one region or virtual network may not need a global edge service. Azure Application Gateway can be a better fit for regional layer-7 load balancing and web application firewall scenarios close to the application. Azure Load Balancer is more appropriate for layer-4 TCP or UDP balancing. A simpler CDN may be sufficient when the only requirement is static content delivery without global application routing or advanced security controls.

Azure Front Door is strongest when the application has internet users across regions, needs one global entry point, benefits from edge caching and acceleration, or requires global failover and edge security. Buyers should choose it because the application delivery architecture benefits from Microsoft's global edge network, not simply because the workload already runs in Azure.

Reviews

No reviews yet

Nobody has reviewed Azure Front Door here yet.