[In preview] Public Preview: Azure Front Door mutual TLS
What the source says
Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is mandatory. Azure Front Door validates the certificate at the edge and forwards it to the origin in the X-Azure-ClientCertificate request header. Require without validation: A client certificate is mandatory, but Azure Front Door does not validate it. The certificate is forwarded in the X-Azure-ClientCertificate header for validation by the origin. Validate when presented: A client certificate is optional. When a certificate is presented, Azure Front Door validates it and forwards it to the origin. Requests without a certificate are allowed to continue. Pass through to the origin: A client certificate is optional. Azure Front Door does not validate it but forwards it to the origin when presented, allowing the origin to perform validation. Azure Front Door supports client certificates issued by public and private certificate authorities. Customers upload the trusted certificate authority chain to Azure Key Vault and associate it with a Front Door custom domain. Learn more .
Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is
Why it matters: The change matters because the official source describes: [In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is
Urgency: Monitor
Next action: Review affected accounts with the customer using the official announcement.
Commercial opportunities
Use the verified change to open a scoped customer conversation.
Technical actions
Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
Does this documented change affect a product or workload in scope?
Risks and objections
The official source does not establish facts beyond the quoted material.
Points to confirm
The effective date is unknown and must be confirmed before scheduling action.
Reading for it_manager_dsi
Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is
Why it matters: The change matters because the official source describes: [In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is
Urgency: Monitor
Next action: Assess technical dependencies and ownership against the official update.
Commercial opportunities
Offer a scoped technical-readiness assessment if the customer confirms impact.
Technical actions
Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
Does this documented change affect a product or workload in scope?
Risks and objections
The official source does not establish facts beyond the quoted material.
Points to confirm
The effective date is unknown and must be confirmed before scheduling action.
Reading for partner_channel
Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is
Why it matters: The change matters because the official source describes: [In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is
Urgency: Monitor
Next action: Prepare a source-backed customer conversation and confirm the affected estate.
Commercial opportunities
Qualify a partner-led assessment only after customer scope is confirmed.
Technical actions
Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
Does this documented change affect a product or workload in scope?
Risks and objections
The official source does not establish facts beyond the quoted material.
Points to confirm
The effective date is unknown and must be confirmed before scheduling action.
Reading for sales_manager
Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is
Why it matters: The change matters because the official source describes: [In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is
Urgency: Monitor
Next action: Review portfolio exposure with account owners using the official source.
Commercial opportunities
Prioritize accounts that confirm affected products or workloads.
Technical actions
Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
Does this documented change affect a product or workload in scope?
Risks and objections
The official source does not establish facts beyond the quoted material.
Points to confirm
The effective date is unknown and must be confirmed before scheduling action.
Evidence and traceability
Each excerpt is linked to the primary source. Current raw version: 388.
Raw capture : 2026-08-26T14:18:57.653130+00:00 — hash cf331c360a9d8e79…
Event
[In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is mandatory. Azure Front Door validates the certificate at the edge and forwards it to the origin in the X-Azure-ClientCertificate request header. Require without validation: A client certificate is mandatory, but Azure Front Door does not validate it. The certificate is forwarded in the X-Azure-ClientCertificate header for validation by the origin. Validate when presented: A client certificate is optional. When a certificate is presented, Azure Front Door validates it and forwards it to the origin. Requests without a certificate are allowed to continue. Pass through to the origin: A client certificate is optional. Azure Front Door does not validate it but forwards it to the origin when presented, allowing the origin to perform validation. Azure Front Door supports client certificates issued by public and private certificate authorities. Customers upload the trusted certificate authority chain to Azure Key Vault and associate it with a Front Door custom domain. Learn more .
[In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is mandatory. Azure Front Door validates the certificate at the edge and forwards it to the origin in the X-Azure-ClientCertificate request header. Require without validation: A client certificate is mandatory, but Azure Front Door does not validate it. The certificate is forwarded in the X-Azure-ClientCertificate header for validation by the origin. Validate when presented: A client certificate is optional. When a certificate is presented, Azure Front Door validates it and forwards it to the origin. Requests without a certificate are allowed to continue. Pass through to the origin: A client certificate is optional. Azure Front Door does not validate it but forwards it to the origin when presented, allowing the origin to perform validation. Azure Front Door supports client certificates issued by public and private certificate authorities. Customers upload the trusted certificate authority chain to Azure Key Vault and associate it with a Front Door custom domain. Learn more .
[In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is mandatory. Azure Front Door validates the certificate at the edge and forwards it to the origin in the X-Azure-ClientCertificate request header. Require without validation: A client certificate is mandatory, but Azure Front Door does not validate it. The certificate is forwarded in the X-Azure-ClientCertificate header for validation by the origin. Validate when presented: A client certificate is optional. When a certificate is presented, Azure Front Door validates it and forwards it to the origin. Requests without a certificate are allowed to continue. Pass through to the origin: A client certificate is optional. Azure Front Door does not validate it but forwards it to the origin when prese
[In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is mandatory. Azure Front Door validates the certificate at the edge and forwards it to the origin in the X-Azure-ClientCertificate request header. Require without validation: A client certificate is mandatory, but Azure Front Door does not validate it. The certificate is forwarded in the X-Azure-ClientCertificate header for validation by the origin. Validate when presented: A client certificate is optional. When a certificate is presented, Azure Front Door validates it and forwards it to the origin. Requests without a certificate are allowed to continue. Pass through to the origin: A client certificate is optional. Azure Front Door does not validate it but forwards it to the origin when prese
[In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is mandatory. Azure Front Door validates the certificate at the edge and forwards it to the origin in the X-Azure-ClientCertificate request header. Require without validation: A client certificate is mandatory, but Azure Front Door does not validate it. The certificate is forwarded in the X-Azure-ClientCertificate header for validation by the origin. Validate when presented: A client certificate is optional. When a certificate is presented, Azure Front Door validates it and forwards it to the origin. Requests without a certificate are allowed to continue. Pass through to the origin: A client certificate is optional. Azure Front Door does not validate it but forwards it to the origin when prese
[In preview] Public Preview: Azure Front Door mutual TLS Mutual TLS, also known as client certificate authentication, enables Azure Front Door to authenticate clients using X.509 certificates before requests reach an application. It helps protect sensitive applications and APIs across business-to-business, Internet of Things, financial services, VPN, and enterprise network scenarios. Customers can choose from four client certificate validation modes: Require and validate: A client certificate is mandatory. Azure Front Door validates the certificate at the edge and forwards it to the origin in the X-Azure-ClientCertificate request header. Require without validation: A client certificate is mandatory, but Azure Front Door does not validate it. The certificate is forwarded in the X-Azure-ClientCertificate header for validation by the origin. Validate when presented: A client certificate is optional. When a certificate is presented, Azure Front Door validates it and forwards it to the origin. Requests without a certificate are allowed to continue. Pass through to the origin: A client certificate is optional. Azure Front Door does not validate it but forwards it to the origin when prese