Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesMedium

A DevOps team is implementing a hybrid deployment infrastructure for a legacy application that requires specific on-premises hardware and software. They need to integrate the CI/CD pipeline in Azure DevOps with this on-premises environment to build and deploy the application. The on-premises environment is isolated and cannot be directly exposed to the internet. Which component is required to enable Azure Pipelines to interact with this isolated on-premises environment?

  1. ASelf-hosted agent
  2. BDeployment Group
  3. CAzure DevOps Services agent
  4. DMicrosoft-hosted agent
Show answer & explanation

Correct answer: A. Self-hosted agent

A self-hosted agent is a software component installed on your own infrastructure (on-premises or cloud) that can run jobs from Azure Pipelines. It's essential for hybrid scenarios where pipelines need to access resources that are not publicly exposed.

Why the other options are wrong

  • B. A Deployment Group is a logical grouping of deployment targets (like VMs with agents), not the agent itself that enables connectivity to an isolated environment.
  • C. Azure DevOps Services agent is a generic term; the specific type needed is 'self-hosted'.
  • D. Microsoft-hosted agents run on Azure-managed infrastructure and cannot access isolated on-premises resources.

Self-hosted Agent (Azure Pipelines)

An Azure Pipelines agent that is installed and managed on your own computing infrastructure (e.g., on-premises server, VM in your VNet), allowing pipelines to access resources not accessible to Microsoft-hosted agents.

  • Runs on customer-managed infrastructure.
  • Required for accessing isolated or on-premises resources.
  • Provides control over machine specifications and installed software.
  • Connects securely to Azure DevOps Services.

Memory trick: Agents are the pipeline's hands; self-hosted agents are YOUR hands in YOUR house.

More Design and implement pipelines questions