An Azure service that provides a hybrid, multi-cloud management platform for APIs.
Hello @DevRaulPlanas-2821
The pattern you described: "cached tokens succeeding while requests that require a new token intermittently fail", narrows the failure to the token-acquisition path. The authentication-managed-identity policy obtains an access token from Microsoft Entra ID, adds it to the backend request, and caches it until expiration.
An unhandled policy-processing failure can return HTTP 500 from the APIM gateway. The specific cause should be available through the APIM trace’s LastError information rather than inferred from the client response alone.
I recommend these checks:
- Capture an APIM request trace during a failed token refresh. APIM now requires a time-limited tracing token; subscription-based tracing and Ocp-Apim-Trace are no longer supported. Review the policy step, LastError.Source, LastError.Reason, LastError.Message, and request ID.
- Confirm outbound TCP 443 access to Microsoft Entra ID. Microsoft documents login.microsoftonline.com and regional Microsoft Entra endpoints as APIM dependencies, and the AzureActiveDirectory service tag covers Microsoft Entra sign-in services.
- Check any firewall, proxy, custom DNS, UDR, or TLS inspection device involved in the outbound path. Verify whether failed requests were translated through the NAT gateway and whether the firewall or proxy recorded a reset, timeout, denied request, or upstream HTTP 500 at the same UTC timestamp. This correlation is derived from standard Azure networking architecture.
- Enable APIM diagnostics in Application Insights or resource logs and correlate failures using the gateway request ID and UTC timestamps.
- Check Azure Service Health for Microsoft Entra ID or API Management events in South Central US during the affected window.
Standard v2 supports outbound VNet integration, but that fact alone doesn’t establish that the failure is a known Standard v2 defect.
I cannot find verified official documentation identifying a known issue specifically causing intermittent managed-identity token-minting HTTP 500 errors on Standard v2 with VNet integration.
If traces show the failure inside authentication-managed-identity and the network path contains no corresponding failure, open an Azure support case. Include the APIM resource ID, region, failed UTC timestamps, gateway request IDs, trace output, identity type and client ID, token resource/audience, VNet configuration, and matching firewall/NAT logs. Microsoft Support can then correlate the requests with APIM and Microsoft Entra backend telemetry.
References:
Managed-identity authentication policy
Debug APIs using request tracing
Integrate APIM with Application Insights
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.