Connect with us

AZURE

Akamai’s API Security Badge Opens Microsoft’s Azure Sales Channel

Akamai’s API Security tool now carries Microsoft’s certified software badge, a Marketplace sales channel into Azure as AI multiplies unmanaged APIs.

Published

on

Akamai earned Microsoft’s Solutions Partner with certified software designation for API Security on June 10, 2026. The badge appears on the company’s Microsoft Marketplace listing and is aimed at Azure sellers as much as at security teams.

Paul Joseph, Akamai’s executive vice president of global sales and services, called it a major milestone that lets customers extend protection natively inside Azure. The same June 10 certified software announcement states that the certification covers interoperability with Microsoft Cloud products and is based on self-attestation by the software owner.

Microsoft’s Badge Buys Akamai a Seat With Azure Sellers

Andrew Smith, general manager of Partner Programs and Experiences at Microsoft, said the designation helps partners stand out and that certified software is easier for Microsoft’s own sellers to find. Certified software solutions are prioritized for those sellers, and a digital badge appears beside the offer on Microsoft Marketplace.

Microsoft’s certified-software benefits documentation says 68% of customers evaluate vendor certifications and badging when they search for software. That is the motion Akamai bought: a listing Microsoft account teams can put in front of shops that already hold Azure commitments, billed through Marketplace, with the partner’s name on a Microsoft-looking mark.

CERTIFIED SOFTWARE DESIGNATION

  • What it scores: Marketplace readiness (including Azure IP co-sell eligibility), a technical review of how the software works with Microsoft Cloud, and a record of customer success.
  • What Microsoft disclaims: The mark is not an offer, endorsement, or proof that the product works, and all buying decisions stay with the customer.
  • Where buyers see it: On the Akamai API Security offer in Microsoft Marketplace and in seller-facing play cards built for co-sell.

Joseph tied the badge to AI. He said APIs are the foundation of almost every digital interaction, and that wide-scale protection has become a business requirement as AI adoption accelerates. The designation does not measure that claim. It measures whether Akamai’s software can be sold next to Azure.

What the Certified Software Designation Requires

Microsoft Learn spells out the bar by solution area. Azure offers must be Azure IP co-sell eligible and must pass a technical review audit for Azure that checks interoperability across data operations, AI and machine learning, customer-deployed services, and control-plane or DevOps scenarios.

The Security path uses a different technical gate. Solutions are reviewed against the Microsoft Sentinel Content hub, or they may qualify through the Microsoft Intelligent Security Association if they plug into another Microsoft security platform. Customer evidence for Security does not have to be public, though Microsoft may still ask the customer to confirm it.

HOW THE AZURE AND SECURITY PATHS DIFFER

Pathway Marketplace bar Technical bar Customer-success bar
Azure Azure IP co-sell eligible Interop audit covering data operations, AI/ML, customer-deployed services, and control plane or DevOps Partner and solution criteria over a trailing 12-month window, including Marketplace billed sales and customer evidence
Security Azure IP co-sell eligible Sentinel Content hub review, or Microsoft Intelligent Security Association for other security platforms Trailing 12-month partner and solution criteria; customer evidence may stay private

Akamai’s release frames the award as a designation for API Security inside the Microsoft AI Cloud Partner Program, with Azure named as the environment customers can extend into. Microsoft’s footnotes on that release are blunt. A certification is specific to interoperability, dated to the review, and controlled afterward by the vendor, whose features can change.

The $450 Million Product Behind the Listing

The software on that listing is the platform Akamai formed after its acquisition of Noname Security. Akamai agreed in May 2024 to buy the API security specialist for about $450 million and closed the deal on June 25, 2024, then folded Noname together with its existing API tools under the Akamai API Security name.

That purchase is the bet the badge is now helping to distribute. Akamai already sold CDN, WAF, and bot controls. Noname added discovery of shadow and zombie APIs, posture scoring, runtime detection, and testing in CI/CD, the work Azure-native gateways often never see because the APIs never enter them.

FROM NONAME TO A MARKETPLACE BADGE

  1. May 7, 2024: Akamai agrees to buy Noname Security for about $450 million.
  2. June 25, 2024: The deal closes and Akamai begins combining the products.
  3. October 1, 2024: A native connector into Akamai Cloud goes generally available; Akamai said it was already used by more than 100 customers, analyzing 300,000-plus APIs and more than half a trillion monthly requests.
  4. April 17, 2025: API Security versions 3.45 and 3.46 add automatic discovery and tagging of GenAI and LLM endpoints, plus Azure Key Vault storage for Azure connector secrets.
  5. June 10, 2026: Microsoft awards the certified software designation for API Security.

The Azure connector is the interoperability story the audit is built to notice. Akamai said the sensor runs in the customer’s Azure environment and inspects API traffic, with secrets held in Key Vault rather than in the connector itself. That is a concrete Azure hook. It is also the kind of hook Microsoft sellers can put on a battlecard.

Four Modules Azure Buyers Find in Marketplace

The Microsoft Marketplace listing describes Akamai API Security as covering APIs from development through production, including legacy estates and newer GenAI, LLM, and MCP server traffic. It maps the pitch to four jobs, then tells buyers the product plugs into gateways, load balancers, and WAFs without a rip-and-replace.

WHAT THE MARKETPLACE LISTING PROMISES

  • Discover: Build an inventory of APIs by count and type, and tag shadow, zombie, and AI-related endpoints.
  • Test: Add checks in CI/CD so issues are found before an API reaches production.
  • Detect: Use machine-learning detection on runtime traffic for leakage, abuse, bots, and attacks, including the OWASP API Top 10.
  • Respond: Push work into existing WAF, SIEM, and ITSM tools instead of a separate console war.

Stas Neyman, a director of product marketing at Akamai, wrote that the 2025 updates also added a compliance dashboard, quicker filters across inventory and incidents, and OpenAPI spec import from on-prem GitHub. The listing is the buyer-facing version of that same stack, now with a Microsoft badge beside the Get-it-now button.

Defender for Cloud Already Inventories Azure APIs

Azure shops that already pay for Microsoft Defender for Cloud do not start from zero. The Defender CSPM plan offers API posture in Defender for Cloud across Azure API Management plus APIs hosted on Function Apps and Logic Apps, with automated onboarding once the API Security Posture Management extension is on.

That native view flags unauthenticated APIs, internet-exposed endpoints, dormant APIs, and APIs that allow unencrypted traffic. On API Management it can sample logs and, with Microsoft Purview, classify sensitive data in paths, query strings, and bodies. Attack-path analysis then ties those APIs to backend VMs, containers, storage, and databases.

Akamai is selling the rest of the map. Defender’s inventory is the Azure-managed control plane. Shadow APIs on third-party gateways, old SOAP stacks, GraphQL services that never registered in APIM, and MCP servers standing up beside Copilot agents sit outside that fence unless someone else watches them. The certified listing is how Akamai asks Microsoft sellers to carry that watch into accounts that already standardized on Azure.

The two tools can sit in the same tenant. They also compete for budget in shops that treat “API security” as one line item. Microsoft did not say the badge ranks Akamai above Defender, and the footnotes say the opposite of a ranking.

Daily API Attacks Rose 113 Percent

Akamai’s 2026 Apps, APIs, and DDoS State of the Internet report said APIs have become the main attack surface, with the average number of daily API attacks up 113% year over year. Telemetry in that report put average attacks per enterprise at 258 in 2025, up from 121 in 2024. About 61% of 2025 API attacks involved unauthorized workflows and abnormal activity, up from 30% in 2024.

The companion 2026 API Security Impact Study, a survey of 1,840 security professionals across six industries and 10 countries, found 87% reported at least one API-related security incident in the prior 12 months. The global median inventory exceeded 5,900 APIs per enterprise, and the top quartile exceeded 29,400. Forty-two percent of incidents were linked to APIs powering AI applications, models, and agents. Average cost sat at $700,000 per organization, with the top quartile above $1.8 million.

AKAMAI’S 2026 API ATTACK TALLY

  • Daily attacks: Average API attacks per enterprise rose from 121 in 2024 to 258 in 2025, a 113% increase.
  • Incident rate: 87% of 1,840 surveyed professionals reported an API-related incident in the prior year.
  • Estate size: Median inventory exceeded 5,900 APIs; the top quartile exceeded 29,400.
  • AI share: 42% of incidents were tied to APIs that serve AI apps, models, or agents.

Those figures are Akamai’s own research, published months before the badge, and they are the pitch Microsoft sellers inherit. On September 3, 2026, Akamai’s corporate account was still pressing the visibility gap rather than the partner plaque, saying only 2 in 10 enterprises know which APIs return sensitive data, including APIs tied to their LLMs.

https://x.com/Akamai/status/2095602793386041363

That gap is what the Marketplace copy means by shadow and zombie APIs. It is also why a co-sell motion into Azure is worth more to Akamai than another logo on a partner page. The accounts already buying GPUs and Copilot seats are the accounts spawning endpoints faster than APIM catalogs can track them.

Microsoft Sellers Get a Play Card for Akamai

Smith’s welcome line treated the award as membership in a seller network, not as a lab result.

Attaining a Solutions Partner with certified software designation is an important way for partners to stand out in the market and demonstrate their proven capabilities in areas of high customer demand. Earning a certified software designation for your solution can help position you to meet the growing demand for cloud-based solutions. We’re pleased to welcome Akamai and the API Security solution to Microsoft’s exclusive growing network of partners with certified software designations.

Andrew Smith, GM, Partner Programs and Experiences, Microsoft, Akamai newsroom statement

The kit that comes with that welcome is ordinary partner machinery: a Marketplace badge, solution play cards for Microsoft sellers, a short video, a battlecard or brief, and certified letters for RFPs. Certified software partners also unlock Partner Reported Azure Consumed Revenue and the ISV Success Advanced Package. Joseph’s quote on the same day stayed on Azure nativeness, saying the designation helps customers extend Akamai’s protection to cloud-native applications inside Azure.

Akamai’s own June and July 2026 posts kept pushing API visibility for AI agents, not the plaque. The badge is paperwork for a sales channel. Azure teams still have to decide whether they need a third-party inventory on top of Defender CSPM, and whether Akamai’s sensors cover the APIs that never touch API Management.

Frequently Asked Questions

What is a Solutions Partner with certified software designation?

It is a per-solution mark in the Microsoft AI Cloud Partner Program for software that is Marketplace-ready, passes a technical interoperability review, and shows customer success. Partner Center now surfaces an Insights panel for the commercial side of that test, tracking Marketplace billed sales, net customer adds, and Marketplace transactions, and Microsoft counts a transaction as the first unique mix of customer, partner, and offer, not each recurring bill.

Does the Microsoft badge mean Akamai API Security is endorsed?

No. Microsoft’s own footnotes say the designation is not an endorsement, guarantee, or proof of effectiveness, that solutions are certified only as of the review date, and that the vendor still controls features afterward. Buyers are told every selection and implementation choice stays with them.

How does Akamai API Security differ from Defender for Cloud API posture?

Defender’s API posture turns on with the Defender CSPM plan plus the API Security Posture Management extension, then inventories APIs on Azure API Management, Function Apps, and Logic Apps. Akamai’s listing is built for mixed estates (gateways, WAFs, load balancers, GenAI, LLM, and MCP servers) and adds active testing in CI/CD plus runtime detection that can feed those same WAFs and SIEMs.

When did Akamai buy the product behind this listing?

Akamai announced the Noname Security agreement on May 7, 2024, and closed it on June 25, 2024, for about $450 million. The company said at announcement that the deal was expected to add about $20 million of revenue in fiscal 2024 and to be slightly dilutive to non-GAAP margin and earnings that year.

Harry edits WinAddons, an independent news site that he owns and runs, covering Windows, Xbox, Azure, Microsoft 365, Teams, OneDrive, Outlook, the software built around them and Microsoft's business. His method comes from ten years in journalism, a reporter's years followed by an editor's, and the bulk of that decade has been spent watching Microsoft ship. His reporting starts with what Microsoft publishes: release notes and KB articles read in full, build numbers checked on an installed machine, MSRC advisories and the CVE records behind them, the Azure status history, lifecycle pages, store listings in the market they apply to, and the earnings releases and filings that carry the company's numbers. Every figure is checked against its source before publication, and a public corrections policy explains how mistakes are fixed and labelled. On security stories he does not publish exploit details before a fix is available, reporting what is affected and what to do instead. Pre-release features are labelled by channel and build, and a rumour is called a rumour. Readers can reach Harry at support@winaddons.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending