An Azure service that provides a cloud content delivery network with threat protection.
Hi Hiroshi Tashiro
Thank you for reaching out in Microsoft Q&A forum,Based on Azure Front Door documentation and your setup, here's what's happening and how to resolve it.
Why You're Being Asked to Validate Every Time
The behavior you're experiencing is expected when using Azure Front Door-managed certificates with an apex domain.
For subdomains like www.example.com, Front Door automatically verifies domain ownership by checking that the CNAME record still points to its endpoint (*.z01.azurefd.net). However, for apex domains like example.com, there's no CNAME record pointing to Front Door's endpoint. Because of this, Front Door cannot perform automatic verification and requires you to revalidate domain ownership before renewing the managed certificate.
This is a documented design limitation, not a bug. There is no supported way to eliminate the revalidation requirement while continuing to use Front Door-managed certificates on an apex domain.
Since your objective is to fully automate certificate rotation and avoid recurring manual domain validation, here's what you need to do.
Use BYOC with Azure Key Vault
Bring Your Own Certificate (BYOC) stored in Azure Key Vault is the only supported approach that will eliminate manual validation, provide fully automated rotation, and work with apex domains.
Here's why this works:
- No manual validation: Certificate renewal happens automatically in Key Vault without triggering Front Door domain revalidation. Key Vault manages the certificate lifecycle and auto-renews it.
- Fully automated rotation: Front Door automatically retrieves the updated certificate version from Key Vault. Zero manual intervention required.
- Works with apex domains: There's no dependency on CNAME verification, so it works perfectly with your apex domain setup.
How to set it up:
- Create a certificate in Azure Key Vault with auto-renewal enabled.
- In Azure Front Door, select "Bring Your Own Certificate (BYOC)" and point to your Key Vault certificate.
- Grant Front Door access to the certificate via Key Vault access policy with Certificate Management permission.
Once configured, Key Vault handles renewal automatically, and Front Door picks up the new certificate version.
Official Documentation
- Domains - Azure Front Door – See "Renew Azure Front Door managed certificates" section
- Apex domains in Azure Front Door – Explains auto-rotation limitation for apex domains
- Configure HTTPS for your custom domain – BYOC setup instructions
- Azure Front Door Managed Certificates FAQ
Kindly let us know if the above helps or you need further assistance on this issue.
Please do not forget to
and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.