Edit

Configure TLS policy on a Front Door custom ___domain

Applies to: ✔️ Front Door Standard ✔️ Front Door Premium

Azure Front Door Standard and Premium offer two mechanisms for controlling TLS policy. You can use either a predefined policy or a custom policy based on your own needs. If you use Azure Front Door (classic) or Microsoft CDN (classic), you continue to use the minimum TLS 1.2 version.

  • Azure Front Door offers several predefined TLS policies. You can configure your Azure Front Door with any of these policies to get the appropriate level of security. The Microsoft Security team configures these predefined policies based on best practices and recommendations. Use the newest TLS policies to ensure the best TLS security.

  • If you need to configure a TLS policy for your own business and security requirements, use a custom TLS policy. By using a custom TLS policy, you have complete control over the minimum TLS protocol version to support, and the supported cipher suites.

In this article, you learn how to configure TLS policy on a Front Door custom ___domain.

Prerequisites

Configure TLS policy

  1. Go to your Azure Front Door profile that you want to configure the TLS policy for.

  2. Under Settings, select Domains. Then select + Add to add a new ___domain.

  3. On Add a ___domain, follow the instructions in Configure a custom ___domain on Azure Front Door and Configure HTTPS on an Azure Front Door custom ___domain to configure the ___domain.

  4. For TLS policy, select the predefined policy from the dropdown list or Custom to customize the cipher suites per your needs.

    Screenshot that shows the TLS policy option in Add a ___domain page.

    Select View policy details to see the supported cipher suites.

    Screenshot that shows the TLS policy details.

    When you select Custom, you can choose the minimum TLS version and the corresponding cipher suites by selecting Select cipher suites.

    Screenshot that shows how to customize your TLS policy.

    Note

    To reuse the custom TLS policy setting from other domains in the portal, select the ___domain in Reuse setting from other ___domain.

  5. After you customize the TLS policy, select Add to add the ___domain.

Verify TLS policy configurations

View the supported cipher suite of your ___domain by using www.ssllabs.com/ssltest or use the sslscan tool.