Bird
Raised Fist0
Azurecloud~10 mins

CDN with custom domains in Azure - Step-by-Step Execution

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Process Flow - CDN with custom domains
Create CDN Profile
↓
Create CDN Endpoint
↓
Add Custom Domain to Endpoint
↓
Validate Domain Ownership
↓
Enable HTTPS (Optional)
↓
Custom Domain Ready for Use
This flow shows how to set up a CDN with a custom domain: create profile, endpoint, add domain, validate ownership, and enable HTTPS.
Execution Sample
Azure
az cdn profile create --name myProfile --resource-group myGroup --sku Standard_Microsoft
az cdn endpoint create --name myEndpoint --profile-name myProfile --resource-group myGroup --origin myapp.azurewebsites.net
az cdn custom-domain create --endpoint-name myEndpoint --profile-name myProfile --resource-group myGroup --hostname www.example.com
az cdn custom-domain enable-https --endpoint-name myEndpoint --profile-name myProfile --resource-group myGroup --hostname www.example.com
This code creates a CDN profile and endpoint, adds a custom domain, and enables HTTPS for secure delivery.
Process Table
StepActionCommandResultNotes
1Create CDN Profileaz cdn profile create --name myProfile --resource-group myGroup --sku Standard_MicrosoftProfile 'myProfile' createdProfile is the container for CDN endpoints
2Create CDN Endpointaz cdn endpoint create --name myEndpoint --profile-name myProfile --resource-group myGroup --origin myapp.azurewebsites.netEndpoint 'myEndpoint' createdEndpoint points to origin server
3Add Custom Domainaz cdn custom-domain create --endpoint-name myEndpoint --profile-name myProfile --resource-group myGroup --hostname www.example.comCustom domain 'www.example.com' addedDomain must be owned and DNS configured
4Validate Domain OwnershipAutomatic or DNS TXT record verificationOwnership validatedEnsures you control the domain
5Enable HTTPSaz cdn custom-domain enable-https --endpoint-name myEndpoint --profile-name myProfile --resource-group myGroup --hostname www.example.comHTTPS enabledSecures traffic with SSL/TLS
6Custom Domain ReadyN/ACustom domain active and serving contentUsers can access CDN via custom domain
💡 All steps completed successfully; CDN with custom domain is ready for use.
Status Tracker
ResourceInitial StateAfter Step 1After Step 2After Step 3After Step 4After Step 5Final State
CDN ProfileNoneCreatedCreatedCreatedCreatedCreatedCreated
CDN EndpointNoneNoneCreatedCreatedCreatedCreatedCreated
Custom DomainNoneNoneNoneAddedValidatedHTTPS EnabledActive
HTTPS StatusDisabledDisabledDisabledDisabledDisabledEnabledEnabled
Key Moments - 3 Insights
Why do we need to validate domain ownership before using a custom domain?
Validation confirms you control the domain to prevent misuse. See execution_table step 4 where ownership is validated before enabling HTTPS.
What happens if HTTPS is not enabled on the custom domain?
Traffic will not be encrypted, which can cause security warnings. Refer to execution_table step 5 where HTTPS is enabled to secure traffic.
Can the CDN serve content without adding a custom domain?
Yes, it serves via the default CDN endpoint hostname. Adding a custom domain is optional for branding and easier access, shown in step 3.
Visual Quiz - 3 Questions
Test your understanding
Look at the execution_table, what is the state of the CDN Endpoint after step 2?
ACreated
BNone
CValidated
DHTTPS Enabled
💡 Hint
Check the 'CDN Endpoint' row in variable_tracker after Step 2.
At which step does the custom domain become active and ready for use?
AStep 3
BStep 4
CStep 6
DStep 5
💡 Hint
Refer to execution_table step 6 and variable_tracker final state for Custom Domain.
If HTTPS is not enabled, what will be the HTTPS status after step 5?
AEnabled
BDisabled
CValidated
DCreated
💡 Hint
Look at the HTTPS Status row in variable_tracker after Step 5.
Concept Snapshot
Azure CDN with Custom Domains:
1. Create a CDN profile to group endpoints.
2. Create an endpoint pointing to your origin.
3. Add your custom domain to the endpoint.
4. Validate domain ownership (via DNS).
5. Enable HTTPS for secure traffic.
6. Custom domain is ready to serve content.
Full Transcript
To set up a CDN with a custom domain in Azure, first create a CDN profile which acts as a container for your CDN endpoints. Next, create a CDN endpoint that points to your origin server where your content is hosted. Then, add your custom domain to this endpoint. You must validate that you own this domain, usually by adding a DNS TXT record. After validation, enable HTTPS to secure the traffic between users and the CDN. Once all these steps are done, your custom domain is active and ready to serve content securely through the CDN.

Practice

(1/5)
1. What is the primary purpose of using a custom domain with Azure CDN?
easy
A. To deliver content using your own website address instead of the default CDN URL
B. To increase the storage capacity of the CDN
C. To reduce the cost of CDN services
D. To disable HTTPS on the CDN endpoint

Solution

  1. Step 1: Understand CDN default behavior

    Azure CDN provides a default URL for content delivery, but it uses a generic domain name.
  2. Step 2: Purpose of custom domain

    Using a custom domain lets you serve content with your own website address, improving branding and user trust.
  3. Final Answer:

    To deliver content using your own website address instead of the default CDN URL -> Option A
  4. Quick Check:

    Custom domain = Own website address [OK]
Hint: Custom domain means your own website address on CDN [OK]
Common Mistakes:
  • Thinking custom domain increases storage
  • Assuming custom domain reduces cost
  • Believing custom domain disables HTTPS
2. Which DNS record type must you create to map your custom domain to an Azure CDN endpoint?
easy
A. CNAME record
B. SRV record
C. TXT record
D. MX record

Solution

  1. Step 1: Identify DNS record for domain aliasing

    CNAME records map one domain name to another, which is needed to point your custom domain to the CDN endpoint.
  2. Step 2: Exclude other DNS record types

    MX is for mail, TXT for text info, SRV for service location, none suitable for domain aliasing.
  3. Final Answer:

    CNAME record -> Option A
  4. Quick Check:

    Custom domain uses CNAME DNS record [OK]
Hint: Custom domain points to CDN via CNAME record [OK]
Common Mistakes:
  • Using MX record for domain mapping
  • Confusing TXT record with CNAME
  • Trying to use SRV record for CDN
3. Given the following Azure CLI command snippet to add a custom domain to a CDN endpoint, what will happen if the DNS CNAME record is not set correctly?
az cdn custom-domain create --endpoint-name myEndpoint --profile-name myProfile --resource-group myGroup --hostname www.example.com
medium
A. The custom domain will be added successfully without any issues
B. The CDN endpoint will automatically create the DNS record
C. The custom domain will be added but HTTPS will be disabled
D. The command will fail with a DNS validation error

Solution

  1. Step 1: Understand DNS validation in Azure CDN

    Azure CDN requires DNS validation to confirm ownership of the custom domain via CNAME record.
  2. Step 2: Effect of missing or incorrect DNS record

    If the CNAME record is missing or incorrect, the command fails with a DNS validation error to prevent misconfiguration.
  3. Final Answer:

    The command will fail with a DNS validation error -> Option D
  4. Quick Check:

    Missing CNAME causes DNS validation error [OK]
Hint: DNS must validate custom domain or command fails [OK]
Common Mistakes:
  • Assuming CDN auto-creates DNS records
  • Thinking custom domain adds without DNS setup
  • Believing HTTPS disables if DNS is wrong
4. You added a custom domain to your Azure CDN endpoint but HTTPS is not working. Which of the following is the most likely cause?
medium
A. The CDN endpoint does not support HTTPS at all
B. You used an A record instead of a CNAME record in DNS
C. You forgot to enable HTTPS on the custom domain in the CDN settings
D. The CDN profile is in a different Azure region than your resource group

Solution

  1. Step 1: Check HTTPS enablement for custom domain

    Azure CDN requires explicit enabling of HTTPS on custom domains to serve secure content.
  2. Step 2: Exclude other causes

    CDN endpoints support HTTPS, A record usage causes DNS issues but not HTTPS directly, region mismatch does not block HTTPS.
  3. Final Answer:

    You forgot to enable HTTPS on the custom domain in the CDN settings -> Option C
  4. Quick Check:

    HTTPS must be enabled on custom domain [OK]
Hint: Enable HTTPS explicitly for custom domain [OK]
Common Mistakes:
  • Assuming HTTPS is automatic
  • Blaming region mismatch for HTTPS failure
  • Using A record instead of CNAME but ignoring HTTPS setting
5. You want to design a scalable Azure CDN solution with a custom domain that supports HTTPS and handles millions of users globally. Which combination of steps is the best practice?
hard
A. Create a CDN profile only, add your custom domain with an A record, disable HTTPS to reduce latency, and rely on a single CDN POP
B. Create a CDN profile and endpoint, add your custom domain with a CNAME DNS record, enable HTTPS with Azure-managed certificates, and use multiple CDN POPs worldwide
C. Create multiple CDN profiles for each region, add custom domains without DNS changes, and enable HTTPS manually with self-signed certificates
D. Use Azure CDN without custom domains, enable HTTPS, and configure DNS to point directly to the origin server

Solution

  1. Step 1: Setup CDN profile and endpoint with custom domain

    Create a CDN profile and endpoint, then add your custom domain using a CNAME DNS record for proper domain mapping.
  2. Step 2: Enable HTTPS and use global CDN POPs

    Enable HTTPS using Azure-managed certificates for security and scalability, and leverage multiple CDN Points of Presence (POPs) worldwide to handle global traffic efficiently.
  3. Final Answer:

    Create a CDN profile and endpoint, add your custom domain with a CNAME DNS record, enable HTTPS with Azure-managed certificates, and use multiple CDN POPs worldwide -> Option B
  4. Quick Check:

    Custom domain + CNAME + HTTPS + global POPs = Best practice [OK]
Hint: Use CNAME, enable HTTPS, and leverage global CDN POPs [OK]
Common Mistakes:
  • Using A record instead of CNAME
  • Disabling HTTPS to save latency
  • Skipping DNS changes for custom domains
  • Relying on single CDN POP for global scale