Microsoft Certified: Azure Developer Associate (AZ-204)Monitor, troubleshoot, and optimize Azure solutionsEasy

A company is using Azure API Management (APIM) to secure and publish its APIs. They have a requirement to restrict API access based on the calling client's IP address. Only requests originating from a specific range of internal IP addresses should be allowed to access a particular API, while all other requests should be rejected. Which APIM policy should be implemented to achieve this?

  1. AValidate JWT policy
  2. BRate limit by key policy
  3. CIP filter policy
  4. DCheck HTTP header policy
Show answer & explanation

Correct answer: C. IP filter policy

The 'IP filter' policy in Azure API Management is specifically designed to allow or deny access to APIs based on the client's IP address or a range of IP addresses, directly fulfilling the requirement to restrict access to internal IP ranges.

Why the other options are wrong

  • A. Validate JWT policy is for authenticating clients using JSON Web Tokens, not for IP-based access restriction.
  • B. Rate limit by key policy controls the number of requests clients can make, not their access based on IP address.
  • D. Check HTTP header policy verifies the presence or value of a header, but it does not filter based on the source IP address of the request.

APIM IP Filter Policy

An Azure API Management policy that controls access to APIs by allowing or denying requests based on the client's IP address or a specified range of IP addresses.

  • Can be configured at the product, API, or operation scope.
  • Supports single IP addresses and CIDR ranges.
  • Helps enforce network-level security boundaries.

Memory trick: To let IPs in or out, the IP filter leaves no doubt.

More Monitor, troubleshoot, and optimize Azure solutions questions