← AZ-400: DevOps from delivery to operations
07 / 8 · 45 MIN

Identity, secrets, and pipeline dependencies

Reduce permanent credentials and limit code receiving access.

Concept and mechanism

A pipeline needs authentication and authorization within a defined scope. Workload identity federation supports a compatible app registration or managed identity without managing a permanent client secret. This does not remove RBAC or authorization for each pipeline to use the service connection. Avoid granting access to every pipeline when only two need the connection. Current documentation describes an issuer transition to Microsoft Entra for new Azure public-cloud connections with single-tenant applications or managed identities. The earlier Azure DevOps issuer has announced retirement on July 1, 2027 within that scope; other clouds and multitenant applications are excluded. Do not generalize the deadline across the entire estate.

Guided application

Inventory connections, tasks, and extensions before authentication migration, using a pilot and recovery criteria. For remaining secrets, log masking is limited: it does not hide substrings of a complete JSON secret. Do not print credentials, and explicitly map secret variables into env only for necessary tasks. In GitHub Actions, configure GITHUB_TOKEN with minimum job permissions; reading code and creating issues do not require write-all. A third-party action executes code within workflow context. Pin the reviewed full SHA to stabilize the consumed revision and retain an update process. The SHA does not prove code safety: combine source review, reduced permissions, and dependency analysis.

IN PRACTICE

A WIF connection works but is authorized for every pipeline. Secretless authentication does not resolve that excessive scope.

Common pitfalls

WIF as absence of RBAC; ignored issuer transition; JSON as complete masking; badge as immutable code.

Related topics: Instrumentation and KQL · Flow, traceability, and handover

Take this idea with you

Control identity, consumer, and code revision for each access.

Create account

Reference: Azure service connections · AZ-400 objectives 2026-07-27