Category
Open ID Connect
-
Protecting APIs with Microsoft Entra ID
This article shows a practical way to protect APIs with Microsoft Entra ID by combining app roles and scopes. You learn how to design clean app registrations, how to map scopes to roles inside the API, and how to derive effective permissions for each request. The example CRM application illustrates how this model keeps authorization predictable, maintainable, and easy to reason about.
-
Building a Web Application that Supports both Azure AD and Azure AD B2C
When Azure AD B2C was first announced several years ago, one of the key selling points were that from an application's point of view, it is just another Azure AD instance. You don't have to make changes to your application to switch between Azure AD and Azure AD B2C.