Failed to update domain secret to BYOC.

Enyu Wang 20 Reputation points Microsoft Employee
2026-01-08T23:02:40.2766667+00:00

I was updating the secret for the custom domain in Azure Front Door to use "Bring your own certificate", it worked for me before, it failed recently for all my changes showing the error as below. Anyone has any idea why this is happening and how I can fix it?

image (1)

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
{count} votes

Answer accepted by question author
  1. Thanmayi Godithi 4,200 Reputation points Microsoft External Staff Moderator
    2026-01-08T23:58:51.07+00:00

    Hi @Enyu Wang,

    Thank you for reaching out on Microsoft Q&A forum.

    As mentioned by the user, the root cause was identified as a limitation in Azure Front Door Control Plane (AFD CP). For keyless customers whose profiles were migrated from 1P to 3P AFD, only 100 custom domains can reference the same SHA-1 certificate thumbprint.

    Once this limit is reached, BYOC updates fail for additional domains, which explains the error encountered.

    Resolution / Workaround: As suggested by the user, the fix is to create a duplicate copy of the certificate/secret in Key Vault and use the duplicated secret for the new domains. The user is coordinating with the security team to implement this.

    This workaround successfully bypasses the thumbprint reference limitation.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.