Skip to content

Details

In Part 3 of our Azure Application Platform Security series, we move further up the application stack to focus on protecting Azure App Service workloads, web applications, APIs, backend services, and AI endpoints.

Modern applications are increasingly exposed through web front ends and APIs. That makes application-layer protection, strong authentication, network isolation, API governance, rate limiting, and secure backend communication essential responsibilities for Cloud and AI Security Engineers.

This session will explore two important security areas: Azure App Service and Web Application Firewall security, and API backend protection using Azure API Management.

About the Session

Cloud-native application security requires protection at several layers.

An application may have a secure operating system and database while still being exposed through vulnerable web endpoints or poorly protected APIs. Security engineers therefore need to consider how users authenticate, how application traffic is inspected, which network paths are allowed, how APIs authorize callers, and how backend connections are protected.

During this session, participants will see how Azure App Service, Azure Application Gateway Web Application Firewall, Microsoft Entra ID, Azure API Management, and AI Gateway can work together as part of a defense-in-depth architecture.

The first part of the session is based on Implement security controls for Azure App Services and Web Application Firewall.
Participants will explore securing App Service with authentication, managed identities, VNet integration and private endpoints, then configuring Azure Web Application Firewall policies with managed and custom rules. Microsoft positions Application Gateway WAF as an edge protection capability for web workloads, including protection from common web exploits.

The second part is based on Implement API backend security using Azure API Management.
Participants will explore API authentication and authorization, JWT validation, OAuth 2.0 integration with Microsoft Entra ID, IP filtering, rate limiting, virtual-network integration, client certificates, mutual TLS, and using AI Gateway to place governance controls in front of AI model endpoints.

What You Will Learn

By the end of the session, participants should understand how to:

  • Secure Azure App Service using authentication, managed identities, VNet integration and private endpoints; configure WAF managed and custom rules; protect web workloads at the application edge; secure APIs with subscription keys, JWT validation and OAuth 2.0; apply IP filtering and rate limiting; protect backend connections with client certificates and mTLS; use Microsoft Entra ID for API authorization; and understand how Azure API Management and AI Gateway can govern access to AI model endpoints.

Who Should Attend?

This session is particularly relevant to Cloud and AI Security Engineers, Azure Security Engineers, Cloud Engineers, Application Security Engineers, DevSecOps Engineers, API Developers, Platform Engineers, Cloud and Security Architects, Azure Administrators, AI Engineers, SOC professionals, and learners preparing for the SC-500 Cloud and AI Security Engineer certification.

It is also valuable for anyone responsible for protecting web applications, APIs, cloud-native workloads, or AI services running on Microsoft Azure.

Why You Should Attend

Modern application security is increasingly about protecting the interfaces through which applications and AI services are consumed.

A secure workload must answer questions such as: Who can access the application? Is the App Service directly exposed to the internet? Are common web attacks being inspected and blocked? How are APIs authenticated? Are clients rate-limited? Can unauthorized IP ranges reach the API? Are backend connections mutually authenticated? And are AI model endpoints governed through a controlled gateway?

This session connects those questions to practical Microsoft Azure security controls.

Whether you are designing cloud applications, protecting APIs, supporting DevSecOps teams, securing AI solutions, or preparing for SC-500, this session will help you understand how to build a more secure application delivery architecture on Azure.

Learn. Build. Protect. Secure the Application Layer.

Related topics

Cloud Security
Cybersecurity
Network Security
Cloud Services
Information Security

You may also like