Microsoft Certified: Azure Developer Associate (AZ-204)Monitor, troubleshoot, and optimize Azure solutionsEasy
An online gaming company uses Azure API Management (APIM) to manage access to its game server APIs. They need to ensure that only authenticated and authorized users can access the game server's `/play` endpoint. The authentication is handled by an external identity provider (IdP) that issues JWTs. After successful authentication, the IdP sends the JWT to the client. The client then includes this JWT in requests to the `/play` endpoint. Which APIM policy configuration should be applied to the `/play` operation to enforce this security requirement?
- AA `rate-limit` policy to control access frequency.
- BAn `ip-filter` policy to restrict access to specific IP ranges.
- CA `check-header` policy to ensure an 'Authorization' header is present.
- DA `validate-jwt` policy with appropriate issuer, audience, and signing key checks.
Show answer & explanationAnswer & explanation
Correct answer: D. A `validate-jwt` policy with appropriate issuer, audience, and signing key checks.
The `validate-jwt` policy is specifically designed to verify JSON Web Tokens (JWTs) received from clients. It can check the token's signature, expiration, issuer, audience, and other claims, ensuring that only valid and authorized tokens grant access to the API.
Why the other options are wrong
- A. A `rate-limit` policy controls request frequency but does not perform authentication or authorization based on a JWT.
- B. An `ip-filter` policy restricts access based on source IP addresses, which is a network-level security measure, not an application-level authentication/authorization based on a JWT.
- C. A `check-header` policy only verifies the presence or value of a header; it cannot validate the complex structure, signature, or claims within a JWT.
APIM validate-jwt Policy
An Azure API Management policy that validates the authenticity and integrity of a JSON Web Token (JWT) included in an API request, enabling secure access control based on token claims.
- Verifies JWT signature using public keys from the issuer.
- Checks token expiration, issuer, and audience.
- Can enforce specific claims for authorization decisions.
Memory trick: For JWTs, APIM's `validate-jwt` is the security guard!