Skip to content

Commit c3776f9

Browse files
committed
,
2 parents d3a0254 + fac57f8 commit c3776f9

3 files changed

Lines changed: 42 additions & 30 deletions

File tree

articles/frontdoor/front-door-faq.yml

Lines changed: 30 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
ms.author: halkazwini
77
ms.service: azure-frontdoor
88
ms.topic: faq
9-
ms.date: 02/24/2026
9+
ms.date: 04/07/2026
1010
title: Azure Front Door frequently asked questions (FAQ)
1111
summary : |
1212
This article provides answers to the most frequently asked questions about Azure Front Door features and functionality. If you don't see the answer to your question, you can contact us through the following channels (in escalating order):
@@ -306,9 +306,9 @@ sections:
306306
questions:
307307

308308
- question: |
309-
What is happening with DigiCerts CNAME Delegation DCV workflow?
309+
What is happening with DigiCert's CNAME Delegation DCV workflow?
310310
answer: |
311-
On 15 August 2025, DigiCert will deprecate support for the legacy CNAME Delegation DCV workflow. DigiCert is transitioning to a new open-source software (OSS) domain control validation (DCV) platform designed to enhance transparency and accountability in domain validation processes. DigiCert will no longer support the legacy CNAME Delegation DCV workflow for domain control validation in the specified Azure services. [Learn more](https://learn.microsoft.com/en-us/azure/security/fundamentals/managed-tls-changes)
311+
Effective August 15, 2025, DigiCert transitioned to a new open-source software (OSS) domain control validation (DCV) platform designed to enhance transparency and accountability in domain validation processes. DigiCert will no longer support the legacy CNAME Delegation DCV workflow for domain control validation in the specified Azure services. [Learn more](https://learn.microsoft.com/en-us/azure/security/fundamentals/managed-tls-changes)
312312
313313
- question: |
314314
Which Azure Front Door SKUs are affected by this change?
@@ -319,32 +319,43 @@ sections:
319319
- Azure CDN from Microsoft (classic)
320320
321321
- question: |
322-
What will happen after 15 August 2025?
322+
What's the current status?
323323
answer: |
324324
Azure Front Door (classic) and Azure CDN from Microsoft (classic):
325-
- Will no longer support for new domain onboarding and new profile creation.
326-
- Will no longer support Azure-managed certificates.
327-
- Automation scripts for these actions will begin to fail.
328-
- Switching to managed certificates on existing domains will no longer be allowed.
329-
- Emergent renewals of managed certificates will not be possible due to the deprecation of CNAME-based validation.
330-
331-
- question: |
332-
What happens to existing managed certificates?
333-
answer: |
334-
Existing managed certificates will be automatically renewed before 15 August 2025 and remain valid until 14 April, 2026. However, any renewal required after 15 August 2025 will not be possible.
325+
- Effective August 15, 2025, no longer support for new domain onboarding,new profile creation, or Azure-managed certificates.
326+
- Effective April 14, 2026, existing managed certificates will be retired.
335327
336328
- question: |
337329
What actions should I take to avoid service disruption?
338330
answer: |
331+
Microsoft will automatically migrate eligible profiles on a "best effort" basis to Azure Front Door Standard/Premium between April 10, 2026 and April 14, 2026, unless you notify us otherwise. Classic and Azure Front Door Standard/Premium SKUs are charged differently. Please refer to the [pricing page](https://azure.microsoft.com/en-us/pricing/details/frontdoor/?msockid=06fc59dfa84d6e0612124fafa9586f44) for details.
332+
333+
If you plan to migrate to Azure Front Door Standard/Premium or switch to BYOC yourself, please notify Microsoft by April 9, 2026 by setting the required feature flag, see instructions below.
334+
335+
You can check the auto-migration eligibility by following [the migration steps](https://learn.microsoft.com/en-us/azure/frontdoor/migrate-tier). If step 1 Validate compatibility succeeds, your profile is eligible. If you proceed with auto‑migration, monitor your email for final migration confirmation and status updates.
336+
337+
**Required action**
338+
339+
Azure CDN from Microsoft (classic)
340+
341+
Before April 9, 2026:
342+
- [Migrate to Azure Front Door Standard or Premium](https://learn.microsoft.com/en-us/azure/cdn/migrate-tier?toc=%2Fazure%2Ffrontdoor%2Ftoc.json) or [move to Bring Your Own Certificate (BYOC)](https://learn.microsoft.com/en-us/azure/cdn/cdn-custom-ssl?toc=%2Fazure%2Ffrontdoor%2Ftoc.json&tabs=option-1-default-enable-https-with-a-cdn-managed-certificate).
343+
- If you plan to migrate to Azure Front Door or move to BYOC yourself before April 14, 2026 or want to opt out of auto migration and willing to risk disruption to the HTTPS traffic, you will need to set a Feature Flag by following [instruction provided](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/preview-features?tabs=azure-portal), and selecting the Feature Flag "Microsoft.Cdn/DoNotAutoMigrateClassicManagedCertificatesProfiles") before April 9, 2026. Doing so will prevent Microsoft from migrating your eligible classic managed certificate profiles to Azure Front Door.
344+
345+
Between April 10, 2026 and April 14, 2026:
346+
- Customers who didn't set the said Feature Flag before April 9, 2026, their profiles will be migrated to Azure Front Door Standard or Premium SKU on a "best effort" basis and should watch for an email related to their migration status.
347+
- Customers who set the said Feature Flag but are still consuming services with classic SKUs will have until April 14, 2026 to complete migration or move to BYOC.
348+
339349
Azure Front Door (classic)
350+
351+
Before April 9, 2026:
352+
- [Migrate to Azure Front Door Standard or Premium](https://learn.microsoft.com/en-us/azure/frontdoor/tier-migration) or [move to Bring Your Own Certificate (BYOC)](https://learn.microsoft.com/en-us/azure/frontdoor/front-door-custom-domain-https?tabs=powershell).
340353

341-
- If you want to create new domains or profiles, or use Azure managed certificates, [migrate to Azure Front Door Standard or Premium](https://learn.microsoft.com/en-us/azure/frontdoor/tier-migration) before 15 August 2025.
342-
- If you're already using Azure managed certificates on existing domains, you can either [Move to Bring Your Own Certificate (BYOC)](https://learn.microsoft.com/en-us/azure/frontdoor/front-door-custom-domain-https?tabs=powershell) or [migrate to Azure Front Door Standard or Premium](https://learn.microsoft.com/en-us/azure/frontdoor/tier-migration) before 15 August 2025.
354+
- If you plan to migrate to Azure Front Door or transition to Bring Your Own Certificate (BYOC) before April 14, 2026, or if you choose to opt out of auto migration and accept the risk of HTTPS traffic disruption, you will need to set a feature flag by following the [instruction provided](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/preview-features?tabs=azure-portal), and selecting the Feature Flag "Microsoft.Cdn/DoNotAutoMigrateClassicManagedCertificatesProfiles" before April 9, 2026. Doing so will prevent Microsoft from migrating your eligible classic managed certificate profiles to Azure Front Door.
343355

344-
Azure CDN from Microsoft (classic)
356+
Between April 10, 2026 and April 14, 2026:
345357

346-
- If you want to create new domains or profiles, or use Azure managed certificates, [migrate to Azure Front Door Standard or Premium](https://learn.microsoft.com/en-us/azure/cdn/migrate-tier?toc=%2Fazure%2Ffrontdoor%2Ftoc.json) before 15 August 2025.
347-
- If you're already using Azure managed certificates on existing domains, you can either [Move to Bring Your Own Certificate (BYOC)](https://learn.microsoft.com/en-us/azure/cdn/cdn-custom-ssl?toc=%2Fazure%2Ffrontdoor%2Ftoc.json&tabs=option-1-default-enable-https-with-a-cdn-managed-certificate) or [migrate to Azure Front Door Standard or Premium](https://learn.microsoft.com/en-us/azure/cdn/migrate-tier?toc=%2Fazure%2Ffrontdoor%2Ftoc.json) before 15 August 2025.
358+
- For customers who do not set the feature flag by April 9, 2026, Microsoft will migrate their profiles to Azure Front Door Standard or Premium SKU on a "best effort" basis. Customers are advised to monitor their email for updates on migration status. Customers who have set the said Feature Flag but are still consuming services with classic SKUs will have until April 14, 2026 to complete migration or move to BYOC.
348359

349360
- name: Billing
350361
questions:

articles/storage/files/storage-files-identity-configure-file-level-permissions.md

Lines changed: 10 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn how to configure Windows ACLs for directory-level and file-le
44
author: khdownie
55
ms.service: azure-file-storage
66
ms.topic: how-to
7-
ms.date: 03/04/2026
7+
ms.date: 04/07/2026
88
ms.author: kendownie
99
# Customer intent: "As a system administrator, I want to configure directory-level and file-level permissions for SMB Azure file shares by using Windows ACLs, so that I can ensure granular access control and enhance security for users accessing shared files."
1010
---
@@ -13,16 +13,17 @@ ms.author: kendownie
1313

1414
**Applies to:** :heavy_check_mark: SMB file shares
1515

16-
Before you can configure directory-level and file-level permissions, you must [assign share-level permissions to an identity](storage-files-identity-assign-share-level-permissions.md) with Azure role-based access control (RBAC). After the share-level permissions propagate, you can configure Windows access control lists (ACLs), also known as NTFS permissions, as described in this article.
16+
Before you can configure directory-level and file-level permissions, you must [assign share-level permissions to an identity](storage-files-identity-assign-share-level-permissions.md) with Azure role-based access control (RBAC). After the share-level permissions propagate, follow the steps in this article to configure Windows access control lists (ACLs), also known as NTFS permissions, for more granular access control.
1717

18-
Before you can configure Windows ACLs, you need to mount the file share with admin-level access.
18+
## Prerequisites
1919

20-
> [!IMPORTANT]
21-
> To configure Windows ACLs for [hybrid identities](/entra/identity/hybrid/whatis-hybrid-identity), you need a client machine running Windows that has unimpeded network connectivity to the domain controller.
22-
>
23-
> If you authenticate with Azure Files by using Active Directory Domain Services (AD DS) or Microsoft Entra Kerberos for hybrid identities, you need unimpeded network connectivity to on-premises Active Directory. If you use Microsoft Entra Domain Services, the client machine must have unimpeded network connectivity to the domain controllers for the domain that Microsoft Entra Domain Services manages. These domain controllers are located in Azure.
24-
>
25-
> For cloud-only identities (preview), there's no dependency on domain controllers, but the client device must be joined to Microsoft Entra ID.
20+
If you want to configure Windows ACLs for [hybrid identities](/entra/identity/hybrid/whatis-hybrid-identity) and the identity source for your storage account is Active Directory Domain Services (AD DS) or Microsoft Entra Kerberos, you need a client machine running Windows that has unimpeded network connectivity to on-premises Active Directory.
21+
22+
If the identity source for your storage account is Microsoft Entra Domain Services, you need a client machine running Windows that has unimpeded network connectivity to the domain controllers for the domain that Microsoft Entra Domain Services manages. These domain controllers are located in Azure.
23+
24+
If your identity source is Microsoft Entra Kerberos and you want to configure Windows ACLs for cloud-only identities (preview), there's no dependency on domain controllers, but the client device must be joined to Microsoft Entra ID.
25+
26+
Before you can configure Windows ACLs, you need to mount the file share with admin-level access.
2627

2728
## How Azure RBAC and Windows ACLs work together
2829

articles/vpn-gateway/vpn-gateway-about-skus-legacy.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -45,13 +45,13 @@ Pricing differs between gateway SKUs. For more information, see [VPN Gateway pri
4545

4646
### <a name="change"></a> Move to a new gateway SKUs
4747

48-
Standard and High Performance SKUs will be deprecated on March 31, 2026. All legacy SKUs use Basic IP address today, and we recommend you use the Azure portal to [migrate a Basic IP address to a Standard IP address](basic-public-ip-migrate-about.md) before the retirement date. As part of Basic IP address migration, your legacy SKU will also be migrated to a newer SKU that's supported by availability zones. For more information, see the [Legacy SKU deprecation](#sku-deprecation) section. For the most up-to-date timeline, see [What's new in Azure VPN Gateway?](whats-new.md).
48+
Standard and High Performance SKUs will be deprecated on June 30th, 2026. All legacy SKUs use Basic IP address today, and we recommend you use the Azure portal to [migrate a Basic IP address to a Standard IP address](basic-public-ip-migrate-about.md) before the retirement date. As part of Basic IP address migration, your legacy SKU will also be migrated to a newer SKU that's supported by availability zones. For more information, see the [Legacy SKU deprecation](#sku-deprecation) section. For the most up-to-date timeline, see [What's new in Azure VPN Gateway?](whats-new.md).
4949

5050
[!INCLUDE [Change to the new SKUs](../../includes/vpn-gateway-gwsku-change-legacy-sku-include.md)]
5151

5252
## SKU deprecation
5353

54-
The Standard and High Performance SKUs will be deprecated on March 31, 2026. All legacy SKUs use Basic IP addresses today, and you can use the Azure portal to [migrate a Basic IP address to a Standard IP address](basic-public-ip-migrate-about.md) before the retirement date. As part of Basic IP migration, your legacy SKU will also be migrated to AZ SKU family.
54+
The Standard and High Performance SKUs will be deprecated on June 30th, 2026. All legacy SKUs use Basic IP addresses today, and you can use the Azure portal to [migrate a Basic IP address to a Standard IP address](basic-public-ip-migrate-about.md) before the retirement date. As part of Basic IP migration, your legacy SKU will also be migrated to AZ SKU family.
5555

5656
For more information, you can:
5757

0 commit comments

Comments
 (0)