TransWikia.com

Is it possible to connect to on-prem API through Azure AD Application Proxy without interactive user login?

Stack Overflow Asked by Sammy Schnor on December 20, 2021

I’d like to connect to an On-Prem API from an external cloud service using the Azure AD Application Proxy. I can connect and use the API by logging in with my Azure AD User in a browser, but would like a code-based-like login to use from my external service.

I’ve been digging through various articles the last couple of days, and it seems not possible without an Azure AD User interactive login. I am able to create an AD user for this service only if needed, but handling the interactive login from code or even through Postman seems troublesome.

Can someone point me in the right direction to solve this cloud-service to on-prem app solution? (unfortunately, I can’t move the on-prem app to Azure).

EDIT: I’ll be looking at using the pass-through option in the App registration, which means i need to handle the authentication and security in my API.

One Answer

Perhaps you could consider using an on-premises data gateway instead, but it depends on where your external cloud service is hosted.

https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-gateway-install

Essentially, if your external cloud service is completely outside your environment and your control, the data gateway can still be used, then you can expose a Logic App as a facade that can integrate with the on-premises data gateway. The external cloud service can then call the logic app to trigger the request, which can be secured by other means e.g. SAS key.

Answered by Tejinder Rai on December 20, 2021

Add your own answers!

Ask a Question

Get help from others!

© 2024 TransWikia.com. All rights reserved. Sites we Love: PCI Database, UKBizDB, Menu Kuliner, Sharing RPP