Lesson 12 / 25
API Management and Logic Apps
Publish APIs safely and automate workflows with connectors.
A front door for APIs, a canvas for workflows
Azure API Management (APIM) sits in front of your backends (Functions, App Service, AKS or external APIs) and gives callers one consistent gateway. It handles subscription keys or token validation, rate limits and quotas, request and response transformation, caching, versioning and a developer portal. Rules are written as policies in XML that run inbound, at the backend and outbound. Azure Logic Apps is a low-code workflow service with hundreds of connectors (Office 365, Salesforce, SAP, SQL, Service Bus) for integration jobs such as "when an invoice email arrives, extract the attachment, save it to blob storage and post to Teams". Use code (Functions) where logic is complex, and Logic Apps where the work is mostly gluing systems together.
APIM policies: validate a token and rate-limit
This inbound policy rejects requests without a valid Entra ID token and limits each subscription to 100 calls a minute.
<policies>
<inbound>
<base />
<validate-jwt header-name="Authorization" failed-validation-httpcode="401">
<openid-config url="https://login.microsoftonline.com/{tenant-id}/v2.0/.well-known/openid-configuration" />
<audiences><audience>api://shop-api</audience></audiences>
</validate-jwt>
<rate-limit calls="100" renewal-period="60" />
</inbound>
<backend><base /></backend>
<outbound><base /></outbound>
</policies>Gateways are not a substitute for backend checks
APIM can validate tokens at the edge, but the backend should still authorise each request. If someone reaches the backend directly, through a misconfigured network rule for example, edge checks do not help. Lock the backend to accept traffic only from APIM.
Quick check: Where would you configure per-client rate limits and JWT validation for a set of APIs?
- Azure API Management policies
- An Event Hubs partition
- A storage account tier
- A VM availability set
Answer
Azure API Management policies — APIM policies handle cross-cutting gateway concerns such as authentication checks and throttling.