With domain fronting you may get 'nsfw_example.com' content from a TLS connection negotiated with 'bank_example.com'.
This can be a security threat (not able to properly filter outbound traffic) and customer A may be unhappy about Azure allowing nsfw content to be distributed over a channel secured under the name of their bank.
CDN customers that are having their stuff blocked because of that are not going to be happy, in general.
Lots of IoC base on DNS as well so that is out of the windows since the malicious traffic is inside TLS...:-/
your standard user agent (e.g. browser) will not send different values in SNI and HTTP Host header.
this is a deliberate action by the user agent to obscure the actual traffic destination.
this can of course be used both for censorship circumvention but also misleading corporate traffic inspection when TLS is not broken, though it's debatable whether that should work in the first place.
Azure originally started on this path in 2021: https://www.microsoft.com/en-us/security/blog/2021/03/26/sec...
Working in the pentest/red team field, I've seen various providers ban consulting companies and red teams from using domain fronting -- however, this doesn't stop the threat actors.