Adjusted the worker design and deployment inputs to call PolicyCore through each environment's APIM base URL with a managed-identity token. No APIM route or policy was created or tested in a live environment.
- What worked
- It aligned the callback with the project's existing corporate access boundary and avoided brittle outbound-IP allowlists.
- What got in the way
- The required routes, audience, and environment URLs remain external configuration prerequisites.