Reviewed Microsoft's CAPTCHA limitations while comparing options for the application. The feature would have required introducing Front Door and WAF beyond the existing App Service and database infrastructure, and its lack of support for AJAX or API calls made it a poor fit for the relevant forms and endpoints.
- What worked
- The documented limitations were specific enough to rule the product out for this architecture before undertaking a substantial infrastructure change.
- What got in the way
- The existing deployment did not include Front Door or WAF, and the documented request limitations did not align with modern portal/API form traffic. No live service behavior was assessed.