A company uses Azure DevOps for its CI/CD pipelines. These pipelines need to frequently update Azure resource configurations, including deploying new Azure Functions and modifying Azure Key Vault access policies. The security team wants to ensure that the CI/CD pipelines authenticate to Azure AD using a method that eliminates the need for manually managed secrets or certificates, and also allows for fine-grained, temporary elevation of privileges when performing sensitive operations.
- AImplement Workload Identity Federation with a service principal and integrate with Azure AD Privileged Identity Management (PIM).
- BStore Azure AD administrator credentials as secure variables in Azure DevOps.
- CUse a system-assigned managed identity for the Azure DevOps agent.
- DConfigure the Azure DevOps service connection to use a Service Principal with a client secret.
Show answer & explanationAnswer & explanation
Correct answer: A. Implement Workload Identity Federation with a service principal and integrate with Azure AD Privileged Identity Management (PIM).
Workload Identity Federation allows the CI/CD pipeline (e.g., Azure DevOps) to authenticate to Azure AD without secrets, using federated credentials. Integrating this with Azure AD PIM enables just-in-time access for the service principal, providing temporary elevated privileges only when sensitive operations are performed, meeting the requirement for fine-grained, temporary privilege elevation.
Why the other options are wrong
- B. Storing administrator credentials in secure variables, even if encrypted, is not a secure or recommended practice for workload identities and doesn't offer temporary privilege elevation.
- C. Azure DevOps agents (if self-hosted on Azure VMs) can use system-assigned managed identities, but this doesn't directly support the CI/CD pipeline's authentication to Azure AD for cross-resource deployments, nor does it inherently provide temporary privilege elevation.
- D. Using a Service Principal with a client secret still requires manual secret management and rotation, which the security team wants to eliminate.
Workload Identity Federation with PIM
A solution combining Workload Identity Federation (secret-less authentication for workloads) with Azure AD Privileged Identity Management (PIM) to enable just-in-time, time-bound access for service principals. This allows CI/CD pipelines or other workloads to authenticate without managing secrets and gain elevated privileges only when needed.
- Eliminates the need for client secrets/certificates for workload authentication.
- PIM provides just-in-time (JIT) and time-bound access to Azure AD roles.
- Ideal for CI/CD pipelines requiring temporary elevated access to Azure resources.
Memory trick: FEDERATE for NO secrets, PIM for JIT powers.