Azure Front Door: Our services aren't available right now (503/502 from Front Door)
Front Door couldn’t get a valid response from your origin — origin down, health probes failing, TLS/host header mismatch, or a timeout.
Seen on:
Azure
Meaning
The page shows an x-azure-ref you can look up. Common: origin certificate name doesn’t match the origin host header, private link/origin firewall blocking Front Door, or responses exceeding the timeout.
Common causes
- Origin unhealthy or probe path failing
- Origin host header/certificate mismatch
- Origin firewall not allowing AzureFrontDoor.Backend service tag
- Response slower than origin timeout
⚡ Quick fix
- Check origin health and probe settings
- Set origin host header to a name the origin’s certificate covers
- Allow the AzureFrontDoor.Backend service tag / X-Azure-FDID check
Detailed fix by platform
Azure CLI
az afd origin show -g rg --profile-name fd --origin-group-name og --origin-name app --query "{host:hostName,hostHeader:originHostHeader,enabled:enabledState}"
How to diagnose
- Reference — x-azure-ref in diagnostics logs
- Health — Origin health %
- TLS — Certificate CN/SAN vs host header
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Azure
- AADSTS50076 Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
- AuthorizationPermissionMismatch Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission
- AADSTS700016 Azure AD (Entra ID): AADSTS700016 Application not found in the directory
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026