An Azure service that provides a hybrid, multi-cloud management platform for APIs.
Hi Vikas,
Yes, you can do this with Microsoft Entra ID. A client-credentials token does not require a user, but it can contain application claims.
For your scenario, I would use an App Role on the API. Assign a role such as Org-ABC or OrganizationCode to each calling application. With client credentials, the assigned app roles are included in the access token in the roles claim.
APIM can then read that claim directly:
<set-variable name="orgCode"
value="@(((Jwt)context.Variables["jwt"]).Claims["roles"][0])" />
You can also use Entra claims mapping/custom claims if you specifically need a custom claim such as organizationCode; Microsoft supports adding custom claims to access tokens using claims mapping policies.
For a simple organisation-to-application mapping, App Roles are usually easier to manage than maintaining an APIM Named Value map. APIM can validate and consume the claim after validating the Entra token.