Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesMedium

A DevOps team is implementing a release pipeline for a critical microservice. The team wants to ensure that before a new version is deployed to production, it passes a series of automated health checks, performance tests, and security scans on a staging environment. Additionally, if any of these checks fail, the deployment to production should be automatically prevented. Which Azure Pipelines feature should the team use to enforce these conditions?

  1. APre-deployment approvals.
  2. BPre-deployment gates.
  3. CTask groups.
  4. DPost-deployment conditions.
Show answer & explanation

Correct answer: B. Pre-deployment gates.

Pre-deployment gates in Azure Pipelines are designed to automatically enforce health, performance, and security conditions before a release proceeds to a target stage. If any configured gate fails, the deployment is automatically halted, preventing problematic releases from reaching production.

Why the other options are wrong

  • A. Pre-deployment approvals require manual intervention and are not automated checks.
  • C. Task groups are for organizing and reusing sets of tasks, not for enforcing automated deployment conditions.
  • D. Post-deployment conditions run after a deployment and are typically for cleanup or notifications, not preventing a deployment.

Pre-deployment Gates

Automated validations that must pass before a release can be deployed to a specific stage in Azure Pipelines.

  • Enforce quality, security, and performance criteria.
  • Prevent problematic releases from reaching production.
  • Can include Azure Monitor alerts, Azure Policy compliance, custom REST APIs.

Memory trick: Gates guard the path to production.

More Design and implement pipelines questions