A company is using Azure DevOps to manage its software development lifecycle. They need to integrate an external security scanning tool into their release pipeline. This tool requires approval from a security team before deploying to production. The approval process involves reviewing the scan results and manually approving the deployment. The security team uses a separate ticketing system, and the approval status needs to be reflected in Azure DevOps. Which Azure DevOps feature should they use to manage this approval process effectively?
- APre-deployment approvals in release pipelines
- BBranch policies on the production branch
- CService hooks to trigger an external approval system
- DManual intervention tasks in release pipelines
Show answer & explanationAnswer & explanation
Correct answer: A. Pre-deployment approvals in release pipelines
Pre-deployment approvals in Azure DevOps release pipelines are specifically designed for this scenario. They pause the pipeline before deployment to an environment (like production) and require designated approvers to manually approve or reject the deployment. While service hooks or manual intervention tasks could be part of a larger solution, the direct and integrated way to enforce approval for deployment in Azure DevOps is through pre-deployment approvals.
Why the other options are wrong
- B. Branch policies apply to code merges, not to deployments in release pipelines.
- C. Service hooks can notify an external system, but they don't block the pipeline for approval within Azure DevOps itself. An additional mechanism would be needed to wait for external approval.
- D. Manual intervention tasks pause a pipeline and wait for input, but they are typically for technical interventions, not formal approval gates that integrate with defined approvers and policies like pre-deployment approvals.
Azure Pipelines Pre-deployment Approvals
A feature in Azure DevOps release pipelines that pauses deployment to an environment and requires explicit approval from designated users or groups before proceeding.
- Configured per environment in a release pipeline.
- Supports multiple approvers and approval policies.
- Can integrate with Azure AD groups for approver management.
- Ensures human gatekeeping before critical deployments.
Memory trick: Pre-deployment approvals are the gatekeepers of production.