How to automatically rotate certificates without domain validation in Azure FrontDoor

Hiroshi Tashiro 110 Reputation points Microsoft Employee
2026-06-15T19:15:54.7233333+00:00

I already know how to rotate certificates and validate domains manually on Azure. For each certificate renewal, I am forced to validate the domain, and I want to automate it.

How can I automate certificate rotation without triggering manual domain validation?

A doc (Domains - Azure Front Door | Microsoft Learn) says there are a few cases where domain validation are forces:

User's image

For our case, 1-3 do not apply, and 4 partially applies. We use custom domain as an apex domain, but do not use CNAME flattening (we just CNAME directly). For example, we use xx-staging-secondary.azure.net as an apex domain and have CNAME records below.

User's image

User's image

Can someone help me how to resolve?.

Azure Front Door
Azure Front Door

An Azure service that provides a cloud content delivery network with threat protection.

0 comments No comments

Answer accepted by question author
Venkatesan S 10,830 Reputation points Microsoft External Staff Moderator
2026-06-16T18:47:58.6066667+00:00

Hi Hiroshi Tashiro

Thank you for reaching out in Microsoft Q&A forum,Based on Azure Front Door documentation and your setup, here's what's happening and how to resolve it.

Why You're Being Asked to Validate Every Time

The behavior you're experiencing is expected when using Azure Front Door-managed certificates with an apex domain.

For subdomains like www.example.com, Front Door automatically verifies domain ownership by checking that the CNAME record still points to its endpoint (*.z01.azurefd.net). However, for apex domains like example.com, there's no CNAME record pointing to Front Door's endpoint. Because of this, Front Door cannot perform automatic verification and requires you to revalidate domain ownership before renewing the managed certificate.

This is a documented design limitation, not a bug. There is no supported way to eliminate the revalidation requirement while continuing to use Front Door-managed certificates on an apex domain.

Since your objective is to fully automate certificate rotation and avoid recurring manual domain validation, here's what you need to do.

Use BYOC with Azure Key Vault

Bring Your Own Certificate (BYOC) stored in Azure Key Vault is the only supported approach that will eliminate manual validation, provide fully automated rotation, and work with apex domains.

Here's why this works:

  • No manual validation: Certificate renewal happens automatically in Key Vault without triggering Front Door domain revalidation. Key Vault manages the certificate lifecycle and auto-renews it.
  • Fully automated rotation: Front Door automatically retrieves the updated certificate version from Key Vault. Zero manual intervention required.
  • Works with apex domains: There's no dependency on CNAME verification, so it works perfectly with your apex domain setup.

How to set it up:

  • Create a certificate in Azure Key Vault with auto-renewal enabled.
  • In Azure Front Door, select "Bring Your Own Certificate (BYOC)" and point to your Key Vault certificate.
  • Grant Front Door access to the certificate via Key Vault access policy with Certificate Management permission.

Once configured, Key Vault handles renewal automatically, and Front Door picks up the new certificate version.

Official Documentation

Kindly let us know if the above helps or you need further assistance on this issue.

Please do not forget to 210246-screenshot-2021-12-10-121802.pngand “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

Was this answer helpful?

2 people found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. SUNOJ KUMAR YELURU 18,736 Reputation points MVP Volunteer Moderator
    2026-06-17T13:36:08.19+00:00

    Hello @Hiroshi Tashiro,

    Thank you for reaching out Q&A forum.

    To automate certificate rotation in Azure Front Door without triggering manual domain validation, you need to ensure that your domain meets the necessary requirements for automatic renewal. Here are the steps:

    1. Domain CNAME Mapping: Ensure that your domain is CNAME-mapped to Azure Front Door and meets the CAA record and domain state requirements. This setup allows Azure Front Door to automatically attempt to rotate your managed certificate if it is within 45 days of expiry.
    2. The auto-rotation job runs every 6-8 hours and typically takes around 24-48 hours to complete. If the auto-rotation fails, the domain validation state will change to ‘Pending validation’, and you can revalidate domain ownership to manually trigger validation if necessary.

    If this answers your query, do click Accept Answer and Up-Vote for the same. And, if you have any further query do let us know.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-06-15T19:16:11.1+00:00

    For Azure Front Door Standard/Premium there are only two ways to avoid manual domain validation at renewal time:

    1. Use Azure Front Door–managed certificates and meet the auto‑rotation prerequisites.
    2. Use Bring Your Own Certificate (BYOC) with Azure Key Vault and let Front Door auto‑rotate the Key Vault secret version.

    Because the domain is an apex domain, managed‑certificate rotation can require revalidation. The documentation states that for apex domains, automated rotation might require domain revalidation and that in non‑direct‑CNAME scenarios revalidation is expected.

    To fully automate renewal without any domain validation step, switch from Azure‑managed certificates to BYOC:

    1. Issue and store the TLS certificate for the apex domain in Azure Key Vault.
    2. In Key Vault, configure automatic renewal (for example via Key Vault certificate policies or an external ACME/automation process) so that a new certificate version is created before expiry.
    3. In Azure Front Door:
      • Create a Secret that references this Key Vault certificate.
      • When selecting the certificate version, choose Latest so that Azure Front Door automatically picks up the newest version when Key Vault rotates it.
    4. Associate this Secret with the apex custom domain using Bring Your Own Certificate (BYOC).

    With BYOC:

    • Domain validation is not required when enabling HTTPS on the custom domain.
    • Front Door automatically rolls out the updated certificate whenever Key Vault creates a new version of the secret; no DNS TXT record or other domain validation is involved.

    If continuing to use Azure Front Door–managed certificates instead of BYOC, there is no supported way to guarantee renewal without potential domain revalidation for apex domains.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.