Share via

Certs in front door not actually using the latest version

Reed at PS 0 Reputation points
2026-02-27T16:19:19.5266667+00:00

I have updated my certs in key vault and it has been over 6 hours and the front door secrets are still using the previous cert version. How can I get this updated to the current version?

Azure Front Door
Azure Front Door

An Azure service that provides a cloud content delivery network with threat protection.

0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Vallepu Venkateswarlu 5,720 Reputation points Microsoft External Staff Moderator
    2026-02-27T16:41:32.96+00:00

    Hi @ Reed at PS,

    Welcome to Microsoft Q&A Platform.

    When you update a certificate in Azure Key Vault that is used by Azure Front Door (Standard/Premium) as a customer-managed TLS certificate, the update behavior depends on how the secret version is configured.

    If you select a specific version of your certificate, you have to reselect the new version manually when you update your certificate.

    As per Microsoft Document: Renew customer-managed TLS certificates

    It takes up to 72 hours for the new version of the certificate/secret to be automatically deployed.

    If the secret version is set to “Latest”, Azure Front Door automatically detects and uses the updated certificate version from Azure Key Vault. However, certificate deployment across the global Front Door infrastructure can take up to 72 hours.

    No manual action is required unless the update has not propagated after this period.

    Please210246-screenshot-2021-12-10-121802.pngand “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.