We recently migrated an API application from Azure Cloud Services to Azure Websites, and some clients are still using our legacy protocol for authentication, which uses cook
This is Something that you can do in the web.config file that is available in your web app.
You can edit it using Visual Studio Online (Monaco) which is a Tools that you add from the Azure Portal.
Read more here : http://enable-cors.org/server_iis7.html