Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A developer is implementing a RESTful API using Azure API Management (APIM) that exposes sensitive customer data. The API backend is hosted on an Azure App Service. To enhance security, all requests to the API must first be authenticated using OAuth 2.0 with Azure Active Directory (AAD) and then authorized based on roles assigned to the user. Which APIM policy should be used to enforce role-based authorization?
- Avalidate-jwt
- Bcheck-header
- Crate-limit-by-key
- Dset-header
Show answer & explanationAnswer & explanation
Correct answer: A. validate-jwt
The `validate-jwt` policy in Azure API Management is specifically designed to validate incoming JWTs (JSON Web Tokens) issued by an OAuth 2.0 provider like Azure AD. It can be configured to check for specific claims within the JWT, including roles, thus enabling role-based authorization.
Why the other options are wrong
- B. The `check-header` policy verifies the existence or value of a specific HTTP header. While it can check for headers, it does not validate the integrity or claims of a JWT for authorization.
- C. The `rate-limit-by-key` policy enforces call rate limits based on a key, which is related to traffic management, not authorization.
- D. The `set-header` policy adds or overwrites HTTP headers in the request or response. It is used for modifying traffic, not for validating authorization tokens.
APIM validate-jwt policy
An Azure API Management policy used to validate JSON Web Tokens (JWTs) presented by clients, ensuring their authenticity and allowing for claim-based authorization.
- Verifies JWT signature, issuer, audience, and expiry.
- Can enforce the presence and values of specific claims (e.g., 'roles').
- Essential for implementing OAuth 2.0 and OpenID Connect authorization in APIM.
Memory trick: JWTs are like ID cards; APIM validates them at the door.