Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planEasy

A software development company is using Azure DevOps for its CI/CD pipelines. They have implemented a security gate in their release pipeline that requires manual approval from a security team lead before deploying to production. This approval process must be auditable and clearly recorded within Azure DevOps. Which Azure DevOps feature should the team configure to implement this security gate?

  1. AEnvironment approvals and checks
  2. BService connection security
  3. CPipeline permissions
  4. DVariable group security
Show answer & explanation

Correct answer: A. Environment approvals and checks

Azure DevOps Environments allow you to define resources and apply checks and approvals, such as a manual approval from a security team lead, before a stage that targets that environment can run. This provides the required auditable security gate.

Why the other options are wrong

  • B. Service connection security controls who can use a service connection, not an approval gate for deployments.
  • C. Pipeline permissions control who can run or edit a pipeline, not a specific manual approval step within a release flow.
  • D. Variable group security controls who can access and manage variables, not a deployment approval process.

Azure DevOps Environment Approvals

A feature in Azure DevOps that enforces manual or automated checks and approvals on an environment before a stage targeting that environment can be executed in a pipeline.

  • Can be configured for pre-deployment or post-deployment checks.
  • Supports manual approvals from specified users or groups.
  • Provides an auditable record of approvals within the pipeline run.

Memory trick: Environments are the Checkpoints for your Pipeline's Journey!

More Develop a security and compliance plan questions