Microsoft Certified: Azure Developer Associate (AZ-204)Monitor, troubleshoot, and optimize Azure solutionsEasy
A company uses Azure API Management (APIM) to expose several internal APIs to external partners. They need to implement a security measure that ensures only authorized clients can access specific API operations. This authorization should be based on claims embedded within a JSON Web Token (JWT) provided by the client. Which APIM policy should they use to enforce this requirement efficiently?
- Asend-request
- Bvalidate-jwt
- Cset-header
- Dcheck-header
Show answer & explanationAnswer & explanation
Correct answer: B. validate-jwt
The `validate-jwt` policy in Azure API Management is specifically designed to validate incoming JWTs, including checking their signature, expiration, and claims, making it the ideal choice for enforcing authorization based on JWT claims.
Why the other options are wrong
- A. The `send-request` policy is used to send a request to an external service, not to validate an incoming JWT.
- C. The `set-header` policy modifies or adds an HTTP header, it doesn't perform any validation on incoming tokens.
- D. The `check-header` policy only validates the presence or value of a specific HTTP header, not the complex structure and claims of a JWT.
APIM validate-jwt policy
An Azure API Management policy used to validate a JSON Web Token (JWT) provided by the client. It can verify signature, expiration, audience, issuer, and specific claims.
- Enforces authorization based on JWT claims.
- Checks token validity and integrity.
- Can be configured to validate specific claims or audiences.
Memory trick: JWTs need validation, APIM's policy is their salvation!