Dan Rios 12/1/2025

Rate limiting Entra External ID Email OTP Events with APIM

Read Original

This article details how to enforce rate limiting on Entra External ID's custom email OTP API endpoint using Azure API Management (APIM). It addresses challenges like user abuse and Microsoft-originating IPs by using the `rate-limit-by-key` policy with the user's email identifier from the OTP payload as the custom counter key.

Rate limiting Entra External ID Email OTP Events with APIM

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week