Azure Front Door: export inventory
Overview
This PowerShell script searches all enabled Azure subscriptions available to the current account, inventories Azure Front Door Standard and Premium profiles, and exports the results to CSV files.
It captures:
- Front Door profiles.
- Front Door endpoints.
- Routes.
- Origin groups and origins.
This is useful when you need to quickly identify:
- Which subscriptions and resource groups contain each Front Door profile.
- Which endpoints and hostnames are exposed.
- Which routes are configured on each endpoint.
- Which origin groups and origins back each profile.
- Which origins are using Private Link integration.
What the script does
- Retrieves enabled subscriptions with
Get-AzSubscription. - Switches context into each subscription with
Set-AzContext. - Reads CDN profiles with
Get-AzResource. - Filters to Azure Front Door Standard and Premium profiles by SKU.
- Uses
Invoke-AzRestMethodto read endpoints, routes, origin groups, and origins. - Flattens the results into separate CSV exports.
- Prints progress to the console while collecting results.
Prerequisites
Install the Azure PowerShell modules if needed:
Install-Module Az -Scope CurrentUserConnect to Azure before running the script:
Connect-AzAccountThe account must have permission to read Azure Front Door profiles and related child resources in the subscriptions being checked.
Output
The CSV files are written under:
.\frontdoor-exportGenerated files:
frontdoor-profiles.csvfrontdoor-endpoints.csvfrontdoor-routes.csvfrontdoor-origins.csv
Profiles CSV columns
SubscriptionNameSubscriptionIdResourceGroupProfileNameLocationSkuResourceId
Endpoints CSV columns
SubscriptionNameSubscriptionIdResourceGroupProfileNameEndpointNameHostNameEnabledState
Routes CSV columns
SubscriptionNameSubscriptionIdResourceGroupProfileNameEndpointNameRouteNameEnabledStatePatternsToMatchSupportedProtocolsForwardingProtocolHttpsRedirectOriginGroupNameCustomDomains
Origins CSV columns
SubscriptionNameSubscriptionIdResourceGroupProfileNameOriginGroupNameOriginNameHostNameHttpPortHttpsPortEnabledStatePriorityWeightAzureOriginIdPrivateLinkResourceIdPrivateLinkLocationPrivateLinkGroupIdPrivateLinkStatus
PowerShell script
$OutputFolder = ".\frontdoor-export"
New-Item -ItemType Directory -Path $OutputFolder -Force | Out-Null
$apiVersion = "2025-04-15"
$profilesOut = @()
$endpointsOut = @()
$routesOut = @()
$originsOut = @()
$subscriptions = Get-AzSubscription |
Where-Object { $_.State -eq "Enabled" }
foreach ($subscription in $subscriptions) {
Write-Host ""
Write-Host "=== $($subscription.Name) ===" -ForegroundColor Yellow
Set-AzContext -SubscriptionId $subscription.Id | Out-Null
$profiles = Get-AzResource `
-ResourceType "Microsoft.Cdn/profiles" `
-ErrorAction SilentlyContinue
foreach ($profile in $profiles) {
# Only AFD Standard/Premium profiles
$profileDetail = Get-AzResource `
-ResourceId $profile.ResourceId `
-ExpandProperties
$skuName = $profileDetail.Sku.Name
if ($skuName -notmatch "AzureFrontDoor") {
continue
}
Write-Host "Processing Front Door profile: $($profile.Name)" -ForegroundColor Cyan
$profilesOut += [PSCustomObject]@{
SubscriptionName = $subscription.Name
SubscriptionId = $subscription.Id
ResourceGroup = $profile.ResourceGroupName
ProfileName = $profile.Name
Location = $profile.Location
Sku = $skuName
ResourceId = $profile.ResourceId
}
# Endpoints
$endpointUri =
"/subscriptions/$($subscription.Id)" +
"/resourceGroups/$($profile.ResourceGroupName)" +
"/providers/Microsoft.Cdn/profiles/$($profile.Name)" +
"/afdEndpoints?api-version=$apiVersion"
try {
$endpointResponse = Invoke-AzRestMethod `
-Method GET `
-Path $endpointUri
$endpointData = $endpointResponse.Content | ConvertFrom-Json
}
catch {
Write-Warning "Unable to read endpoints for $($profile.Name)"
continue
}
foreach ($endpoint in $endpointData.value) {
$endpointsOut += [PSCustomObject]@{
SubscriptionName = $subscription.Name
SubscriptionId = $subscription.Id
ResourceGroup = $profile.ResourceGroupName
ProfileName = $profile.Name
EndpointName = $endpoint.name
HostName = $endpoint.properties.hostName
EnabledState = $endpoint.properties.enabledState
}
# Routes
$routeUri =
"/subscriptions/$($subscription.Id)" +
"/resourceGroups/$($profile.ResourceGroupName)" +
"/providers/Microsoft.Cdn/profiles/$($profile.Name)" +
"/afdEndpoints/$($endpoint.name)" +
"/routes?api-version=$apiVersion"
try {
$routeResponse = Invoke-AzRestMethod `
-Method GET `
-Path $routeUri
$routeData = $routeResponse.Content | ConvertFrom-Json
foreach ($route in $routeData.value) {
$customDomains = @(
$route.properties.customDomains |
ForEach-Object {
if ($_.id) {
($_.id -split "/")[-1]
}
}
)
$routesOut += [PSCustomObject]@{
SubscriptionName = $subscription.Name
SubscriptionId = $subscription.Id
ResourceGroup = $profile.ResourceGroupName
ProfileName = $profile.Name
EndpointName = $endpoint.name
RouteName = $route.name
EnabledState = $route.properties.enabledState
PatternsToMatch = ($route.properties.patternsToMatch -join ", ")
SupportedProtocols = ($route.properties.supportedProtocols -join ", ")
ForwardingProtocol = $route.properties.forwardingProtocol
HttpsRedirect = $route.properties.httpsRedirect
OriginGroupName = if ($route.properties.originGroup.id) {
($route.properties.originGroup.id -split "/")[-1]
} else { "" }
CustomDomains = ($customDomains -join ", ")
}
}
}
catch {
Write-Warning "Unable to read routes for endpoint $($endpoint.name)"
}
}
# Origin groups
$originGroupUri =
"/subscriptions/$($subscription.Id)" +
"/resourceGroups/$($profile.ResourceGroupName)" +
"/providers/Microsoft.Cdn/profiles/$($profile.Name)" +
"/originGroups?api-version=$apiVersion"
try {
$originGroupResponse = Invoke-AzRestMethod `
-Method GET `
-Path $originGroupUri
$originGroups = ($originGroupResponse.Content | ConvertFrom-Json).value
}
catch {
Write-Warning "Unable to read origin groups for $($profile.Name)"
continue
}
foreach ($originGroup in $originGroups) {
$originUri =
"/subscriptions/$($subscription.Id)" +
"/resourceGroups/$($profile.ResourceGroupName)" +
"/providers/Microsoft.Cdn/profiles/$($profile.Name)" +
"/originGroups/$($originGroup.name)" +
"/origins?api-version=$apiVersion"
try {
$originResponse = Invoke-AzRestMethod `
-Method GET `
-Path $originUri
$origins = ($originResponse.Content | ConvertFrom-Json).value
}
catch {
Write-Warning "Unable to read origins for $($originGroup.name)"
continue
}
foreach ($origin in $origins) {
$privateLink = $origin.properties.sharedPrivateLinkResource
$originsOut += [PSCustomObject]@{
SubscriptionName = $subscription.Name
SubscriptionId = $subscription.Id
ResourceGroup = $profile.ResourceGroupName
ProfileName = $profile.Name
OriginGroupName = $originGroup.name
OriginName = $origin.name
HostName = $origin.properties.hostName
HttpPort = $origin.properties.httpPort
HttpsPort = $origin.properties.httpsPort
EnabledState = $origin.properties.enabledState
Priority = $origin.properties.priority
Weight = $origin.properties.weight
AzureOriginId = $origin.properties.azureOrigin.id
PrivateLinkResourceId = $privateLink.privateLink.id
PrivateLinkLocation = $privateLink.privateLinkLocation
PrivateLinkGroupId = $privateLink.groupId
PrivateLinkStatus = $privateLink.status
}
}
}
}
}
$profilesOut |
Export-Csv "$OutputFolder\frontdoor-profiles.csv" `
-NoTypeInformation -Encoding UTF8
$endpointsOut |
Export-Csv "$OutputFolder\frontdoor-endpoints.csv" `
-NoTypeInformation -Encoding UTF8
$routesOut |
Export-Csv "$OutputFolder\frontdoor-routes.csv" `
-NoTypeInformation -Encoding UTF8
$originsOut |
Export-Csv "$OutputFolder\frontdoor-origins.csv" `
-NoTypeInformation -Encoding UTF8
Write-Host ""
Write-Host "Front Door export complete: $OutputFolder" -ForegroundColor Green