
Explanation:
Box 1: Azure AD
Authorization workflow
A user or application acquires a token from Azure AD with permissions that grant access to the backend-app.
Box 2: Azure API Management
The token is added in the Authorization header of API requests to API Management.
API Management validates the token by using the validate-jwt policy.
If a request doesn't have a valid token, API Management blocks it.
If a request is accompanied by a valid token, the gateway can forward the request to the API.
Reference:
https://docs.microsoft.com/en-us/azure/api-management/api-management-howto-protect-backend-with-aad
https://docs.microsoft.com/en-us/azure/api-management/api-management-access-restriction-policies#ValidateJWT