Using Webservices we have the ability to define custom authentication schemes like Kerberos.
App services on the other hand only has username/password authentication. Is this secure enough and how would you argue that for good IT security governance?