Setting on a point-to-site VPN gateway using Microsoft Entra ID authentication; it contains the app ID of the Azure VPN Client or of a custom app. Only a single Audience value is allowed per gateway.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Audience in context, with comparison tables and the common traps.
Terms in this definition
- Point-to-site VPN
Connection type in which single client machines, rather than whole sites, tunnel into an Azure virtual network gateway. App Service gateway-required VNet integration relies on it too.
- Keyless authentication
Recommended way of calling AI services and models: rather than sending an API key, the caller presents a Microsoft Entra ID token and is authorised through an RBAC role.
- CONTAINS
Searches columns with a full-text index for words, phrases, prefixes, inflected forms or synonyms; you use it as a predicate in
WHERE. - App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Azure VPN Client
Microsoft's VPN app for Windows 11 and macOS, needed for point-to-site connections that authenticate with Entra ID; you set it up by importing the azurevpnconfig.xml file from the profile package.
Related terms
- API Management validate-jwt policy
API Management inbound policy validating a JWT's issuer, audience, signature and required claims, for instance using the Microsoft Entra OpenID configuration. By default it answers 401 when a token is absent or invalid.
- Custom audience
Lets each point-to-site gateway admit only certain groups: register an app, set its client ID as that gateway's Audience and authorise the Azure VPN Client app as a client, creating one such registration per gateway.
- Microsoft-registered Azure VPN Client app
App ID that Microsoft has already registered, set as the Audience for point-to-site authentication with Entra ID, so you neither register an app yourself nor grant separate admin consent.
- validate-jwt
Before API Management passes a request on to the back end, this policy confirms the JWT has the expected issuer, audience and claims.
- Workspace app
Content such as reports and dashboards, bundled together and published from a Power BI workspace so an audience can use it without being able to edit it. Only Pro or PPU licence holders can create one.