A healthcare provider is deploying a new patient portal application to Azure. The application's backend APIs are exposed through Azure API Management (APIM). Due to strict regulatory compliance, all API traffic must be routed through an Azure Application Gateway for Web Application Firewall (WAF) protection and then to APIM. APIM must then route traffic to backend services hosted in a private Azure Virtual Network (VNet). Which APIM deployment mode is required to ensure APIM can communicate with both the Application Gateway and the private VNet backend services?
- AInternal mode
- BHybrid mode
- CExternal mode
- DConsumption mode
Show answer & explanationAnswer & explanation
Correct answer: A. Internal mode
Internal VNet mode for APIM places the APIM gateway and management endpoints exclusively within the VNet. While this hides APIM from public internet, it allows APIM to reach private backends within the VNet. To make APIM accessible from a public Application Gateway, the Application Gateway would be configured with a public IP and then route traffic to the APIM's internal VNet IP, fulfilling both requirements.
Why the other options are wrong
- B. Hybrid mode is not a standard APIM deployment mode; APIM VNet integration is either external (public IP endpoint) or internal (private IP endpoint).
- C. External mode exposes APIM publicly and allows it to reach public backends but does not directly place it within a private VNet for accessing private backends without additional VNet integration.
- D. Consumption mode is a serverless option that does not support VNet integration for private backends.
APIM Internal VNet Mode
An Azure API Management deployment option where the APIM instance is injected into an Azure Virtual Network (VNet) and exposed via a private IP address. This enables secure access to private backend services within the VNet.
- APIM endpoints are only accessible from within the VNet.
- Requires a Load Balancer or Application Gateway for public access.
- Enables secure communication with VNet-isolated backend services.
Memory trick: Internal for private, External for public, but sometimes private needs a public face!