Azure Front Door strips Accept-Ranges header from origin responses

Paul Mcilreavy 0 Reputation points
2026-02-03T03:14:51.7766667+00:00

Summary

When using Azure Front Door Premium, the Accept-Ranges: bytes response header returned by our origin server is stripped before the response reaches the client. This behaviour is not explicitly documented.

Environment

  • Azure Front Door SKU: Premium
  • Origin: Azure App Service with private link
  • Caching & Compression: Disabled

Observed Behaviour

Direct to origin (without Front Door):

HTTP/2 206
content-type: application/octet-stream
accept-ranges: bytes
content-range: bytes 0-49/26629
...

Via Azure Front Door:

HTTP/2 206
content-type: application/octet-stream
content-range: bytes 0-49/26629
x-cache: CONFIG_NOCACHE
...

Note: accept-ranges header is missing from the Front Door response.

Testing Performed

  • Confirmed the origin returns Accept-Ranges: bytes when accessed directly
  • Confirmed the Range request functionality works correctly through Front Door (HTTP 206, correct Content-Range)

We found that Accept-Ranges is listed as a "reserved header" in the Rule set actions documentation, which states these headers "can't be modified using rules engine actions."

However:

  1. The documentation doesn't state that Front Door actively strips this header from origin responses
  2. The documentation doesn't explain why this header is reserved or stripped
  3. Microsoft's own troubleshooting documentation shows example responses through Front Door that include Accept-Ranges: bytes, suggesting the behaviour may not be universal

Questions

  1. Is Azure Front Door stripping Accept-Ranges from origin responses by design?
  2. If yes, what is the rationale for this behaviour?
  3. Are there any configuration options that would allow this header to pass through to clients?
  4. Can this behaviour be documented more explicitly in the Azure Front Door documentation?

Impact

We have integration tests that validate the presence of Accept-Ranges in API responses. While we can update these tests to validate range functionality differently (by testing actual 206 responses), we would like to understand the expected behaviour for architectural documentation purposes.

Azure Front Door
Azure Front Door

An Azure service that provides a cloud content delivery network with threat protection.


1 answer

Sort by: Newest
  1. AI answer

    2026-02-03T03:15:03.89+00:00

    Azure Front Door does not explicitly document the behavior of stripping the Accept-Ranges header from origin responses. However, it is noted that certain headers, including Accept-Ranges, are considered reserved headers and cannot be modified using rules engine actions. This implies that Azure Front Door may not allow these headers to pass through as they are, potentially as a design choice to maintain consistency or security in how headers are handled.

    1. Is Azure Front Door stripping Accept-Ranges from origin responses by design?
      Yes, it appears that Azure Front Door strips the Accept-Ranges header from origin responses, although this behavior is not explicitly documented.
    2. If yes, what is the rationale for this behavior?
      The rationale is not clearly stated in the documentation, but it may relate to the handling of reserved headers to ensure consistent behavior across different requests and responses.
    3. Are there any configuration options that would allow this header to pass through to clients?
      No, as Accept-Ranges is a reserved header, there are no configuration options available to allow it to pass through to clients.
    4. Can this behavior be documented more explicitly in the Azure Front Door documentation?
      This would be a valid request for Microsoft to consider, as clearer documentation could help users understand the expected behavior regarding reserved headers like Accept-Ranges.

    This behavior impacts integration tests that validate the presence of Accept-Ranges, and while you can adjust tests to check for the functionality of range requests, understanding the expected behavior is crucial for architectural documentation.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.