AAD API Azure API management OAuth2

Azure API Management – What’s what in OAuth2 related settings?

I decided to create a simple one-pager highlighting different settings in Azure API management related to validating JWT Tokens in Oauth2 based flows.

Typical source of confusion can be the developer portal related settings. For the picture I tried to outline which settings are related to developer portal and which validating JWT tokens in the API policies.

Click here for full size version
  • This picture excludes the full details of identity provider and client/API configuration (Another picture and blog post worth of material)


Authorize developer accounts by using Azure Active Directory – Azure API Management | Microsoft Docs

Protect API backend in API Management using OAuth 2.0 and Azure AD – Azure API Management | Microsoft Docs

