Load Balancer vs Application Gateway vs Front Door vs Traffic Manager

Four Azure services balance traffic, and two questions tell them apart: is it web traffic that needs layer 7, and is it regional or global? Each service on a 2x2 grid, plus three exam traps.

By Tony Rough

  • AZ-700
  • AZ-104
  • AZ-305
  • networking
  • exam traps

Azure has four services that all “balance traffic”: Azure Load Balancer, Application Gateway, Azure Front Door and Traffic Manager. Exam questions like to make them look interchangeable. They aren’t, and two questions sort them out.

The two questions

  1. Is it web traffic that needs layer 7? That is, HTTP or HTTPS where you want to route by URL path or host name, terminate TLS, or put a web application firewall in front.
  2. Is it regional or global? Balancing across machines inside one region, or across deployments in several regions.

Put the answers on a grid and each service gets its own square:

Regional Global
Layer 7 (web) Application Gateway Front Door
Layer 4 / any protocol Load Balancer Traffic Manager (DNS)

Azure Load Balancer: regional, layer 4

Load Balancer works at layer 4: TCP and UDP. It passes connections straight through to the virtual machines (or scale set instances) in its backend pool, which makes it fast, with very high throughput and very low latency. It can be public (internet-facing) or internal (a private frontend inside a virtual network).

What it can’t do is anything that needs to read the request: no URL-based routing, no TLS termination, no WAF.

Application Gateway: regional, layer 7

Application Gateway is a reverse proxy. The client’s connection ends at the gateway, and the gateway opens its own connection to the backend. That lets it:

It’s deployed into a virtual network in one region.

Front Door: global, layer 7

Front Door runs at Microsoft’s edge locations around the world. Users connect to the nearest edge, and Front Door carries the request over Microsoft’s network to the best healthy origin, in whichever region that is. It fails over between regions quickly, caches content like a CDN, and has its own WAF.

Traffic Manager: global, DNS-based

Traffic Manager never touches the traffic. It answers the DNS query with the address of the best endpoint (by priority, performance, weight, geography and so on), and the client then connects to that endpoint directly. So it works for any protocol, but:

For global layer 4 traffic there’s also a second option now: the cross-region tier of Azure Load Balancer.

Three traps

  1. Traffic Manager isn’t a proxy. If the requirement mentions TLS offload, path-based routing, WAF or caching, Traffic Manager is wrong however “global” the scenario sounds.
  2. Application Gateway is regional. A web app deployed in several regions needs a global front: put Front Door in front, and keep an Application Gateway in each region behind it if you also need regional layer 7 routing or WAF close to the app.
  3. Only the layer 7 services run a WAF: Application Gateway and Front Door. Load Balancer and Traffic Manager can’t.

Pick it in five seconds

You need… Choose
TCP or UDP inside one region Load Balancer
A web app in one region, with path routing or a WAF Application Gateway
A web app across regions, with edge acceleration or caching Front Door
Any protocol across regions, steered by DNS Traffic Manager

Real designs often combine them, for example Front Door globally, Application Gateway regionally, and an internal Load Balancer in front of the database tier. Ask the two questions for each hop.

Go deeper

Load balancing gets three chapters in the AZ-700 study guide: Load Balancer and Traffic Manager (chapter 9), Application Gateway (chapter 10) and Front Door (chapter 11). It’s also in chapter 13 of the AZ-104 study guide and the networking chapter of the AZ-305 study guide. Facts checked against Microsoft Learn’s Load balancing options guide on 4 October 2026.

The books in this post

More from the blog

All posts