Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium

A software development company is building a new multi-tenant SaaS application on Azure. The application's backend consists of several Azure API Management (APIM) instances that expose APIs to various client applications. Each client application belongs to a different tenant in Azure Active Directory (AAD) and needs to access the APIM APIs using its own identity. The solution must ensure that APIM can securely validate incoming access tokens issued by AAD for any tenant, without explicitly configuring each tenant's details in APIM. Which APIM policy configuration will allow this behavior?

  1. AUse the `validate-jwt` policy with the `audience` set to the APIM API's App ID URI and the `issuer` URL containing `{tenantid}`.
  2. BUse the `validate-jwt` policy with a fixed `audience` and a specific `issuer` URL for a single tenant.
  3. CUse the `validate-jwt` policy with the `audience` set to the APIM API's App ID URI and the `openid-config` URL pointing to `https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration`.
  4. DUse the `validate-jwt` policy with `audience` set to `*` and `issuer` set to `https://sts.windows.net/`.
Show answer & explanation

Correct answer: C. Use the `validate-jwt` policy with the `audience` set to the APIM API's App ID URI and the `openid-config` URL pointing to `https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration`.

For multi-tenant applications, APIM needs to validate JWTs issued by any Azure AD tenant. The `openid-config` URL for the common endpoint (`https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration`) allows APIM to dynamically discover the issuer signing keys and validate tokens from any tenant. The `audience` must still match the APIM API's expected audience (its App ID URI).

Why the other options are wrong

  • A. While `{tenantid}` can be used, the more robust and recommended approach for multi-tenant validation is using the `common` endpoint for `openid-config` which handles dynamic tenant discovery.
  • B. This configuration is suitable for single-tenant applications, not multi-tenant, as it hardcodes a specific issuer.
  • D. Setting `audience` to `*` is insecure and allows any token to be accepted, and `https://sts.windows.net/` is an older issuer URL, not the recommended v2.0 endpoint for multi-tenant applications.

APIM validate-jwt for Multi-tenant

The `validate-jwt` policy in Azure API Management can be configured for multi-tenant applications by pointing the `openid-config` URL to the Azure AD 'common' endpoint. This allows APIM to dynamically validate JWTs issued by any Azure AD tenant without specific per-tenant configuration.

  • Uses the `https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration` endpoint.
  • Dynamically discovers public keys for JWT validation.
  • The `audience` parameter must match the App ID URI of the API.

Memory trick: To validate tokens from many, use the common key.

More Implement Azure security questions