Forum Discussion
How to setup customer to obtain AADB2C token for an API exposed through APIM
You need machine-to-machine tokens for external customers in addition to APIM subscription keys. Client credentials is appropriate only for confidential applications acting as themselves; it does not represent an interactive user. In the Azure AD B2C tenant, register the protected API and expose application permissions, register one confidential client per customer, grant the required permission, and have an administrator consent. The customer requests a token from the B2C policy token endpoint using client_credentials and the API’s .default scope. In APIM, keep the subscription-key check and add an inbound validate-jwt policy using the B2C OpenID configuration, expected audience, issuer, and required application claim or role. Store identifiers as named values and test invalid audience, expired token, missing role, and revoked secret. Client credentials in Azure AD B2C is documented as preview, and B2C is unavailable to new customers. For a new design, evaluate Microsoft Entra External ID before committing to B2C.
Jamony Thanks for the information above. The problem I see with client credentials is that, firstly, it is still in public preview. Secondly, I will have to register a application registration per customer and give them the secret for this application registration. This will require secret renewal after expiry and manual steps. So, it becomes unmanageable for large customer base. Please correct me if I am misunderstanding something.
I was looking at this video, which shows different scenario's:-
https://www.youtube.com/watch?v=JTKpunPpYi8
Scenario 3 in this one seems quite interesting which relies on user account but he has explained this process for the "Try me" function on developer portal, which has user interaction. But in my case it will be machine-to-machine. Is there anyway that can be used in machine-machine scenario?