# Front Door (classic) Profiles With Many Routing Rules and Domains

Canonical: https://www.pointfive.co/efficiency-hub/inefficiencies/front-door-classic-profiles-with-many-routing-rules-and-domains

Azure Front Door (classic) uses an older pricing model that charges for configuration as well as traffic: every routing rule is billed per hour, custom...

By: PointFive

Updated: 2026-09-28

[Cloud Efficiency Hub](https://www.pointfive.co/efficiency-hub) 

The short version

Azure Front Door (classic) uses an older pricing model that charges for configuration as well as traffic: every routing rule is billed per hour, custom domains beyond the first 100 are billed monthly, inbound data is billed per GB, and edge-to-client egress rates are higher than on Front Door Standard and Premium.

PointFive Research

Cloud cost research at PointFive

Azure service

[Azure Front Door](https://www.pointfive.co/efficiency-hub/cloud-services/azure-front-door)

Category

[Networking](https://www.pointfive.co/efficiency-hub/service-category/networking)

Reference

CER-0413

Type

Outdated Version

## Explanation

Why the waste happens and who it affects.

Classic profiles that have grown to dozens or hundreds of routing rules, or many custom domains, pay these meters every hour of every month. Standard and Premium do not charge per routing rule or for the first 100 domains, and Microsoft states they have a lower total cost of ownership.

Classic is also a retiring product. Microsoft no longer allows new classic profiles or new domain onboarding, and Front Door (classic) retires on March 31, 2027, so these profiles have to move anyway. Azure Advisor flags classic profiles with a large number of domains or routing rules, recommending migration to Standard or Premium to save costs. Migration is not automatically cheaper for every shape of workload: Microsoft's own examples show request-heavy workloads and estates with many separate profiles can cost more after a one-to-one migration, so the cost has to be modeled first.

## Billing model

The pricing dimensions that drive this cost.

Classic and Standard/Premium bill on different dimensions; Microsoft's pricing comparison gives example rates.

Classic routing rules

Each rule billed per hour, at a higher rate for the first 5 rules than for additional rules (Microsoft's example rates are 0.03 USD and 0.012 USD per rule per hour)

Classic domains and inbound data

Custom domains beyond the first 100 billed monthly per domain, and inbound data transfer billed per GB

Classic egress

Edge-to-client data transfer priced across 5 zones at higher unit rates than Standard and Premium

Standard and Premium

A monthly base fee per profile plus per-request and per-GB charges, with routing rules and the first 100 custom domains free

## How to detect

5 checks to find it in your estate.

- Review the Azure Advisor cost recommendation Consider migrating to Front Door Standard/Premium, raised when a classic profile contains a large number of domains or routing rules

- List Microsoft.Network/frontDoors resources and count routing rules and frontend endpoints per profile; every rule is billed hourly, so profiles with dozens or hundreds of rules carry the largest configuration charge

- From the classic invoice and the Request Count and Billable Response Size metrics, estimate the Standard or Premium cost with the pricing calculator as Microsoft's cost assessment describes, and compare it with the current bill

- Count how many classic profiles exist per application or environment, since migrating each one to its own Standard or Premium profile adds a base fee per profile

- Look for classic resources left behind after a completed migration; Microsoft recommends deleting them and sends an Azure Advisor reminder

## How to fix

4 ways to remove the waste.

- Migrate classic profiles to Standard or Premium with Microsoft's zero-downtime migration tool, choosing Standard unless managed WAF rule sets, bot protection or Private Link to origins are needed

- Where many classic profiles exist, consolidate them into a small number of multi-endpoint Standard or Premium profiles instead of migrating one-to-one, to avoid multiplying base fees

- For request-heavy workloads, model the per-request meter before migrating, and remove unnecessary classic profiles such as temporary test environments first

- Delete the classic resource after migration completes, and finish migrations well before the March 31, 2027 retirement, after which classic resources can no longer be managed

## Documentation

Vendor references for pricing and configuration.

- [Compare Pricing Between Azure Front Door Tiers  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/frontdoor/understanding-pricing)

- [Azure Front Door (classic) retirement FAQ  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/frontdoor/classic-retirement-faq)

- [Cost recommendations - Azure Advisor  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/advisor/advisor-reference-cost-recommendations)

- [Pricing - Front Door  azure.microsoft.com](https://azure.microsoft.com/en-us/pricing/details/frontdoor/)

## Related inefficiencies

[Browse the library](https://www.pointfive.co/efficiency-hub)

- Azure Front Door  CER-0412

### [Multiple Front Door Standard or Premium Profiles With Few Endpoints](https://www.pointfive.co/efficiency-hub/inefficiencies/multiple-front-door-standard-or-premium-profiles-with-few-endpoints)

Azure Front Door Standard and Premium charge a fixed monthly base fee for every profile, on top of request and data transfer charges. A single profile can hold several endpoints, each with its own routes and custom domains, yet teams often...

Networking

- Azure NAT Gateway  CER-0319

### [Idle Azure NAT Gateway Attached to Subnet Without Active Workloads](https://www.pointfive.co/efficiency-hub/inefficiencies/idle-azure-nat-gateway-attached-to-subnet-without-active-workloads)

Azure NAT Gateways are commonly deployed to provide outbound internet connectivity for resources within virtual network subnets. Over time, the workloads that originally required this outbound access may be scaled down, migrated, or...

Networking

- Azure Private Link  CER-0318

### [Orphaned Private Endpoints After Target Service Deletion](https://www.pointfive.co/efficiency-hub/inefficiencies/orphaned-private-endpoints-after-target-service-deletion)

Azure Private Endpoints are network interfaces that provide private connectivity from a virtual network to Azure PaaS services such as Storage Accounts, SQL Databases, or Key Vaults. When the target service behind a private endpoint is...

Networking

---
Source: the public page above. Product screenshots and illustrative interfaces are examples, not live customer data.

