Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesHard

A DevOps team is responsible for managing several Azure Kubernetes Service (AKS) clusters across different subscriptions. They need to configure Azure Pipelines to deploy applications to these clusters securely. The security policy dictates that service principals should not be used directly for authentication, and instead, a more secure, managed identity-based approach should be employed. Which type of Azure Pipelines service connection, leveraging a modern authentication method, should the team use?

  1. AAzure Resource Manager service connection with a service principal (manual registration).
  2. BGeneric service connection with username and password.
  3. CExternal Git service connection with SSH keys.
  4. DAzure Resource Manager service connection with Workload Identity federation (automatic).
Show answer & explanation

Correct answer: D. Azure Resource Manager service connection with Workload Identity federation (automatic).

Azure Resource Manager service connections with Workload Identity federation (automatic) are the recommended modern and secure way to authenticate Azure Pipelines to Azure resources, including AKS. This approach eliminates the need for managing service principal secrets by leveraging OIDC and managed identities, aligning with the security policy.

Why the other options are wrong

  • A. While a common method, it involves managing service principal secrets, which the policy aims to avoid.
  • B. Username/password is highly insecure and not suitable for automated deployments.
  • C. External Git connections are for source code repositories, not for deploying to Azure resources.

ARM Service Connection with Workload Identity

An Azure Pipelines service connection type that uses Workload Identity federation for secure, secret-less authentication to Azure resources.

  • Eliminates the need to manage service principal secrets.
  • Leverages OpenID Connect (OIDC) and managed identities.
  • Recommended secure authentication for Azure Pipelines to Azure.

Memory trick: Workload Identity federates trust, no secrets needed.

More Design and implement pipelines questions