Abhay Chandramouli Thanks for posting your question in Microsoft Q&A. I assume you have already reviewed Calculate Effective Policy in the policy editor to check the policy evaluation order for the scope. This may have worked at APIM Test tab since by default, Origin header was not passed to the gateway and hence cors policy was not applied.
Quickly reviewing the policy snippet, you are looking to allow certain list of allowed origins (from variable "allowedOriginsList") or default origin (from variable "defaultOrigin") otherwise it should be denied. Correct?
I suggest you enable tracing using Ocp-Apim-Trace header in your front-end app as described in the doc and validate request headers such as Origin, Method and then evaluate the results like below:
This will help investigating the cause of the failure.
I hope this helps and let me know if any questions or still looking for assistance.
If you found the answer to your question helpful, please take a moment to mark it as Yes for others to benefit from your experience. Or simply add a comment tagging me and would be happy to answer your questions.