Microsoft Certified: Azure Developer Associate (AZ-204)Monitor, troubleshoot, and optimize Azure solutionsMedium

A company uses Azure API Management (APIM) to expose its backend APIs. They want to ensure that only authorized client applications can consume these APIs. The client applications will authenticate using OAuth 2.0 and obtain JSON Web Tokens (JWTs) from an identity provider. You need to configure APIM to validate these JWTs before forwarding requests to the backend. Which policy should you implement in APIM?

  1. ACross-domain policy
  2. BCheck HTTP header policy
  3. CValidate JWT policy
  4. DSet header policy
Show answer & explanation

Correct answer: C. Validate JWT policy

The 'Validate JWT' policy in Azure API Management is specifically designed to enforce authentication by validating JSON Web Tokens (JWTs) issued by an identity provider, ensuring that only requests with valid tokens are forwarded to the backend APIs.

Why the other options are wrong

  • A. Cross-domain policy (CORS) is for managing cross-origin resource sharing, not for JWT authentication.
  • B. Check HTTP header policy is for verifying the presence or value of a header, but it does not perform cryptographic validation of a JWT.
  • D. Set header policy is for adding or modifying HTTP headers, not for validating JWTs.

APIM Validate JWT Policy

An Azure API Management policy used to enforce authentication by validating JSON Web Tokens (JWTs) in incoming requests.

  • Validates JWT signature against a specified key.
  • Checks claims such as issuer, audience, and expiry.
  • Can be configured to require specific claims.

Memory trick: Secure your APIs, validate the token, let no bad request be spoken.

More Monitor, troubleshoot, and optimize Azure solutions questions