Microsoft Certified: DevOps Engineer ExpertDesign and implement source controlMedium

A software development company is using Feature Branch Git workflow. They want to ensure that before any pull request (PR) can be merged into the 'main' branch, a build pipeline must successfully complete, and at least two reviewers must approve the changes. Additionally, the build pipeline should run automatically whenever a new commit is pushed to the feature branch associated with an active PR. Which combination of Azure DevOps branch policies and pipeline triggers should they configure?

  1. ASet up a build validation policy for all feature branches, require minimum 2 reviewers for 'main', and configure the build pipeline with a Scheduled trigger.
  2. BRequire a successful build validation policy for 'main', use code review work items, and configure the build pipeline with a Manual trigger.
  3. CRequire a successful build validation policy for 'main', require minimum 2 reviewers for 'main', and configure the build pipeline with a CI trigger on feature branches.
  4. DRequire a successful build validation policy for 'main', require minimum 2 reviewers for 'main', and configure the build pipeline with a Pull Request trigger.
Show answer & explanation

Correct answer: D. Require a successful build validation policy for 'main', require minimum 2 reviewers for 'main', and configure the build pipeline with a Pull Request trigger.

To enforce a successful build and reviewer approvals before merging to 'main', branch policies are used. The 'Build validation' policy ensures a successful build, and 'Minimum number of reviewers' enforces approvals. To have the build run automatically on new commits in a PR, the build pipeline needs a Pull Request trigger, which starts a build when a PR is created or updated.

Why the other options are wrong

  • A. Setting up build validation for all feature branches is overkill and a Scheduled trigger will not react to new commits on feature branches for PRs.
  • B. Code review work items don't enforce approval before merge, and a Manual trigger requires human intervention, failing the 'automatically' requirement.
  • C. A CI trigger on feature branches would build every commit to the feature branch, not specifically tied to the PR context or merging into 'main'. While it builds, the PR trigger is more appropriate for PR-specific validation.

Azure DevOps Pull Request Triggers & Branch Policies

Pull Request (PR) triggers in pipelines initiate builds when PRs are created or updated, while Branch Policies enforce conditions (e.g., successful build, reviewer approval) that must be met before a PR can be merged into a target branch.

  • PR triggers ensure builds run for every PR change.
  • Build validation policy prevents merging if the build fails.
  • Minimum reviewers policy enforces code review before merge.

Memory trick: Think of PR policies as a gatekeeper for the main branch: the build must pass, and two guards must approve before the gate opens, all triggered by your request.

More Design and implement source control questions