API Management Service: Intermittent 500 Errors During Managed Identity Token Minting

DevRaulPlanas-2821 0 Reputation points
2026-10-08T15:17:35.1266667+00:00

Problem description

I am experiencing intermittent 500 errors when attempting to mint managed-identity tokens in my Azure API Management Service instance. The errors occur during outbound proxy tunnel requests to login.microsoftonline.com or login.windows.net, particularly when fetching tokens for authentication purposes. The issue appears to be isolated to this service and does not involve backend responses.

Environment

Azure API Management Service, StandardV2, South Central US, VNet integration on haveli-base-test-gw-vnet/apim-integration, resource group haveli-base-rg.

What I've already tried

I have reviewed the available case details and diagnostic information. No API Management restarts or service upgrades were observed during the incident window. Network configurations, including NAT gateway and NSG rules, have been checked and remain unchanged. I also verified that the gateway's token cache scope and behavior are as expected, with cached tokens succeeding and live token fetches failing.

Current status

I am seeking assistance to understand why the proxy tunnel requests are failing with a 500 status code, whether this is a known issue with StandardV2 + VNet integration, and what steps I can take to resolve or mitigate the problem.

Azure API Management
Azure API Management

An Azure service that provides a hybrid, multi-cloud management platform for APIs.


1 answer

Sort by: Most helpful
  1. Allan Solomon Mejia 10,305 Reputation points
    2026-10-08T17:25:45.42+00:00

    Hello @DevRaulPlanas-2821

    The pattern you described: "cached tokens succeeding while requests that require a new token intermittently fail", narrows the failure to the token-acquisition path. The authentication-managed-identity policy obtains an access token from Microsoft Entra ID, adds it to the backend request, and caches it until expiration.

    An unhandled policy-processing failure can return HTTP 500 from the APIM gateway. The specific cause should be available through the APIM trace’s LastError information rather than inferred from the client response alone.

    I recommend these checks:

    1. Capture an APIM request trace during a failed token refresh. APIM now requires a time-limited tracing token; subscription-based tracing and Ocp-Apim-Trace are no longer supported. Review the policy step, LastError.Source, LastError.Reason, LastError.Message, and request ID.
    2. Confirm outbound TCP 443 access to Microsoft Entra ID. Microsoft documents login.microsoftonline.com and regional Microsoft Entra endpoints as APIM dependencies, and the AzureActiveDirectory service tag covers Microsoft Entra sign-in services.
    3. Check any firewall, proxy, custom DNS, UDR, or TLS inspection device involved in the outbound path. Verify whether failed requests were translated through the NAT gateway and whether the firewall or proxy recorded a reset, timeout, denied request, or upstream HTTP 500 at the same UTC timestamp. This correlation is derived from standard Azure networking architecture.
    4. Enable APIM diagnostics in Application Insights or resource logs and correlate failures using the gateway request ID and UTC timestamps.
    5. Check Azure Service Health for Microsoft Entra ID or API Management events in South Central US during the affected window.

    Standard v2 supports outbound VNet integration, but that fact alone doesn’t establish that the failure is a known Standard v2 defect.

    I cannot find verified official documentation identifying a known issue specifically causing intermittent managed-identity token-minting HTTP 500 errors on Standard v2 with VNet integration.

    If traces show the failure inside authentication-managed-identity and the network path contains no corresponding failure, open an Azure support case. Include the APIM resource ID, region, failed UTC timestamps, gateway request IDs, trace output, identity type and client ID, token resource/audience, VNet configuration, and matching firewall/NAT logs. Microsoft Support can then correlate the requests with APIM and Microsoft Entra backend telemetry.

    References:

    Managed-identity authentication policy

    APIM policy error handling

    Debug APIs using request tracing

    APIM network configuration

    Integrate APIM with Application Insights


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.