Azure Front Door - Custom Domain certificate provisioning is incorrect.

Vince Rogers 50 Reputation points
2025-11-06T02:13:59.8633333+00:00

Ever since the FD outage last week, when I try to onboard a new custom domain to an azure front door endpoint, the certificate is misconfigured and results in a net::ERR_CERT_COMMON_NAME_INVALID

The certificate name mismatch is due to the fact that it's issued to *.azureedge.net, rather than the appropriate custom domain. In this specific example it's https://sacredportion.outgiven.org/

The domain was configured in the same fashion that many other domains are currently working. The cname is established and points to the endpoint. The domain is validated and associated with a route, the the certificate shows as provisioned successfully and serving traffic.

Attempting to navigate to the URL however shows the invaid name error.

Common Name (CN)

*.azureedge.net

Organization (O)

Microsoft Corporation

Azure Front Door
Azure Front Door

An Azure service that provides a cloud content delivery network with threat protection.


Answer accepted by question author
Anonymous
2025-11-06T06:56:56.39+00:00

Hi Vince Rogers,

The temporary Service Management restrictions on Azure Front Door have been lifted on 5th November and customers can now resume their configuration changes.

 

The Azure portal also reflects this update as a banner:

 

User's image

 

The backend team is actively monitoring the platform & in case of any issues, we will reach out to the backend team for further assistance.

For more understating , please provide the details that we have requested in private message.

Hope you find this comment helpful ,if yes, please “up-vote” for the information provided , this can be beneficial to community members.

Thanks

Was this answer helpful?

0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Vince Rogers 50 Reputation points
    2025-11-06T11:15:53.11+00:00

    It did turn out to be a timing issue, and if you wait long enough it seems to clear up. I've been able to deploy several new custom domains successfully after waiting long enough for the configuration to propagate. I'm used to it being fairly immediate, so hopefully it returns to normal wait times.

    Was this answer helpful?


  2. Anonymous
    2025-11-06T02:23:30.7133333+00:00

    Hi Vince Rogers,

    Thanks for contacting Microsoft Q&A forum,

    We understand that while you trying to onboard a new custom domain to an azure front door endpoint, the certificate is mis-configured and results in provisioning is incorrect,

    As we all know there was a block temporarily , so we request you to follow the below recent updates from AFD & retry configuration after some time & wait for the propagation time.

    Configuration & propagation for all create, update, delete, WAF, and cache purge operations for Azure Front Door and CDN profiles is enabled , it might take up to 45 minutes for added safety.

    (Azure Front Door frequently asked questions (FAQ) | Microsoft Learn).

    Hope you find this comment helpful ,if yes, please “up-vote” for the information provided , this can be beneficial to community members.

    Kindly let us know if you have any additional questions.

    Thanks

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.