Unfortunately the most common use-case of fronting is phishing and other scams that do make our lives worse. There's a legit anti-censorship angle but it is not the major use-case.
your standard user agent (e.g. browser) will not send different values in SNI and HTTP Host header.
this is a deliberate action by the user agent to obscure the actual traffic destination.
this can of course be used both for censorship circumvention but also misleading corporate traffic inspection when TLS is not broken, though it's debatable whether that should work in the first place.
Azure originally started on this path in 2021: https://www.microsoft.com/en-us/security/blog/2021/03/26/sec...
Working in the pentest/red team field, I've seen various providers ban consulting companies and red teams from using domain fronting -- however, this doesn't stop the threat actors.