I am currently developing a single-page webapp using an angular forntend and a python backend. Both are deployed as a service inside a google app engine. The angular frontend uses the URL of the backend service to access the APIs of the backend while the URL of the frontend is used to acces the application.
I already restricted access by using the firewall provided by google app engine. I now want to authenticate and authorise users. I want to give access to a predefined group of users using Azure AD. Only these users should be able to open the Frontend. They should not be able to acces the Backend by its URL but of course be able to acces the data provided by the backend via the Frontend. There are no user specific functionalities. Every user sees the same frontend and has access to the same data.
It is hard for me to approach this task as I never done these things. Has anybody done this? What steps in general should I take? Do I have to change the angular frontend or is it possible to just register my app in Azure AD and configure everything there? Any thoughts or sources would be appreciated.
Cheers,
Tom