title | titleSuffix | description | services | author | ms.service | ms.topic | ms.date | ms.author |
---|---|---|---|---|---|---|---|---|
Protect API in API Management using OAuth 2.0 and Microsoft Entra ID |
Azure API Management |
Learn how to secure user access to an API in Azure API Management with OAuth 2.0 user authorization and Microsoft Entra ID. |
api-management |
dlepow |
api-management |
article |
04/27/2022 |
danlep |
[!INCLUDE api-management-availability-all-tiers]
In this article, you'll learn high level steps to configure your Azure API Management instance to protect an API, by using the OAuth 2.0 protocol with Microsoft Entra ID.
For a conceptual overview of API authorization, see Authentication and authorization to APIs in API Management.
Prior to following the steps in this article, you must have:
- An API Management instance
- A published API using the API Management instance
- A Microsoft Entra tenant
Follow these steps to protect an API in API Management, using OAuth 2.0 authorization with Microsoft Entra ID.
-
Register an application (called backend-app in this article) in Microsoft Entra ID to protect access to the API.
To access the API, users or applications will acquire and present a valid OAuth token granting access to this app with each API request.
-
Configure the validate-jwt policy in API Management to validate the OAuth token presented in each incoming API request. Valid requests can be passed to the API.
Details about OAuth authorization flows and how to generate the required OAuth tokens are beyond the scope of this article. Typically, a separate client app is used to acquire tokens from Microsoft Entra ID that authorize access to the API. For links to more information, see the Next steps.
Using the Azure portal, protect an API with Microsoft Entra ID by first registering an application that represents the API.
For details about app registration, see Quickstart: Configure an application to expose a web API.
-
In the Azure portal, search for and select App registrations.
-
Select New registration.
-
When the Register an application page appears, enter your application's registration information:
- In the Name section, enter a meaningful application name that will be displayed to users of the app, such as backend-app.
- In the Supported account types section, select an option that suits your scenario.
-
Leave the Redirect URI section empty.
-
Select Register to create the application.
-
On the app Overview page, find the Application (client) ID value and record it for later.
-
Under the Manage section of the side menu, select Expose an API and set the Application ID URI with the default value. If you're developing a separate client app to obtain OAuth 2.0 tokens for access to the backend-app, record this value for later.
-
Select the Add a scope button to display the Add a scope page:
- Enter a new Scope name, Admin consent display name, and Admin consent description.
- Make sure the Enabled scope state is selected.
-
Select the Add scope button to create the scope.
-
Repeat the previous two steps to add all scopes supported by your API.
-
Once the scopes are created, make a note of them for use later.
[!INCLUDE api-management-configure-validate-jwt]
-
A user or application acquires a token from Microsoft Entra ID with permissions that grant access to the backend-app.
-
The token is added in the Authorization header of API requests to API Management.
-
API Management validates the token by using the
validate-jwt
policy.-
If a request doesn't have a valid token, API Management blocks it.
-
If a request is accompanied by a valid token, the gateway can forward the request to the API.
-
-
To learn more about how to build an application and implement OAuth 2.0, see Microsoft Entra code samples.
-
For an end-to-end example of configuring OAuth 2.0 user authorization in the API Management developer portal, see How to authorize test console of developer portal by configuring OAuth 2.0 user authorization.
-
Learn more about Microsoft Entra ID and OAuth2.0.
-
For other ways to secure your back-end service, see Mutual certificate authentication.