You are configuring an Azure DevOps build pipeline. This pipeline needs to securely access a private feed in Azure Artifacts to download internal NuGet packages. The pipeline runs on a Microsoft-hosted agent. You want to ensure that the pipeline uses the correct authentication without hardcoding credentials or using a personal access token (PAT) directly in the YAML. Which authentication mechanism is automatically available and recommended for this scenario?
- AService principal authentication configured in a variable group.
- BUser-managed personal access token (PAT) stored as a secure file.
- COAuth token provided by the build service identity.
- DBasic authentication with username and password in pipeline variables.
Show answer & explanationAnswer & explanation
Correct answer: C. OAuth token provided by the build service identity.
Azure DevOps pipelines, by default, run under a 'Build Service' identity. This identity automatically receives an OAuth token that can be used to authenticate with other Azure DevOps services, including Azure Artifacts feeds within the same organization, without requiring explicit credential management in the pipeline YAML.
Why the other options are wrong
- A. While service principals can be used, the build service identity's OAuth token is automatically available and simpler for intra-organization communication.
- B. Using a user's PAT, even if secure, ties the pipeline to a specific user and requires manual rotation, which is not ideal for automated processes.
- D. Hardcoding credentials or storing them in plain variables is a security risk and should be avoided.
Azure DevOps Build Service Identity
A built-in service identity (Project Collection Build Service / Project Build Service) that Azure DevOps pipelines run under, automatically providing an OAuth token for secure interaction with other Azure DevOps services.
- Automatically generated for each project/organization.
- Used for pipeline authentication to internal Azure DevOps resources.
- Permissions can be managed like a regular user or group.
Memory trick: Think of the Build Service Identity as a loyal robot assistant for your pipeline: it has its own secure ID (OAuth token) to access internal resources without you needing to give it your personal keys.