如何安全防护Azure预生产Web应用?无需修改代码的访问控制方案
Hey Stefan, this is such a common pain point when managing staging and production environments without wanting to touch app code—let me walk you through some tried-and-true solutions that fit your needs perfectly:
1. Azure Front Door: Your Frontline Authentication Gateway
This is my top recommendation because it handles all auth and authorization logic before requests even reach your Web App—no code tweaks required:
- Route all pre-production traffic through Front Door first. Then, enable Azure AD Authentication on your Front Door custom domain:
- Pick "Azure Active Directory" as the auth type and link your tenant.
- Set the allowed audience to your pre-production Web App's client ID so tokens are valid for your app.
- Next, lock it down to specific roles:
- Create a custom Azure AD role (like
Pre-Prod Access) and add only the users who need staging access to it. - In Front Door's auth settings, turn on "Claims-based authorization" and add a rule that checks if the user's
rolesclaim includes your custom role value.
- Create a custom Azure AD role (like
- Bonus: Front Door also gives you CDN caching, WAF protection, and global load balancing—so you get security and performance upgrades in one go.
2. Azure Application Gateway + Azure AD Conditional Access
If you already use Application Gateway in your environment, you can leverage its built-in capabilities to secure pre-production:
- Configure Application Gateway to enforce Azure AD Authentication before forwarding requests to your Web App.
- Set up an Azure AD Conditional Access policy targeted at the Application Gateway's service principal. Add a rule that only allows users with your specific AD role to access the pre-production gateway endpoint.
- This works great if you want to keep your existing gateway infrastructure and add auth on top.
3. Tweak Azure App Service's Built-in AD Auth (No Code Needed)
You mentioned trying built-in AD auth but struggling with role-based access—here's how to make it work without touching your app:
- First, head to your pre-production Web App's Azure AD registered app, edit the application manifest, and add a custom role definition (example snippet):
"appRoles": [ { "allowedMemberTypes": ["User"], "description": "Grants access to pre-production environment", "displayName": "Pre-Prod Access", "id": "<generate-a-unique-guid>", "isEnabled": true, "value": "PreProductionAccess" } ] - Assign users to this role: Go to the Azure AD "Enterprise Applications" section, find your Web App, and add users/groups to the custom role you just created.
- Finally, in your App Service's "Authentication" settings, enable "Claims validation" and add a rule that checks if the user's
rolesclaim equalsPreProductionAccess. Only users with this role will be allowed in.
4. Azure API Management (APIM) as a Proxy
If your Web App can be proxied through APIM (great for APIs or web apps), this is another solid option:
- Set up your pre-production Web App as a backend service in APIM.
- Create an API in APIM, enable Azure AD Authentication, and add a policy that checks for your custom AD role in the user's token claims.
- All pre-production traffic must go through APIM—unauthorized requests get blocked before they ever hit your app.
Quick Recap
If you want a lightweight, no-additional-service solution, go with the tweaked App Service AD auth. If you need extra security layers (like WAF) or global access controls, Azure Front Door is the way to go. Both options let you lock down pre-production to specific AD roles without touching your app code.
内容的提问来源于stack exchange,提问作者Simon Krumböck

