Courseiva

Two Ways to Limit Who Can Approve a Production Release

Your release pipeline deploys to multiple environments sequentially: Dev, QA, Staging, Production. You need to implement manual approval gates before Staging and Production deployments. Which TWO configurations should you use? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse post-deployment approvals (which happen after deployment) with pre-deployment approvals (which gate the deployment), or they incorrectly think branch policies or manual validation tasks are the correct way to add manual approval gates in a release pipeline.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the 'Approvals and gates' settings in the release pipeline stage.

The 'Approvals and gates' settings in a release pipeline stage allow you to configure pre-deployment approvals, which require designated users to approve the deployment before it proceeds. This is the standard mechanism in Azure DevOps for implementing manual approval gates. Option E is correct because adding a pre-deployment approval gate specifically to the Staging and Production stages ensures that deployments to these environments are blocked until the required approvals are granted, meeting the requirement for manual approval before Staging and Production.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a post-deployment approval gate to the Dev and QA stages.

    Why it's wrong here

    Post-deployment approvals run after the stage has already deployed, so they cannot prevent the deployment from starting or act as a pre-flight checkpoint. Since the requirement is to gate the release before it proceeds to later environments, placing post-deployment gates on Dev and QA does not satisfy that need.

  • ✓

    Use the 'Approvals and gates' settings in the release pipeline stage.

    Why this is correct

    In classic release pipelines, the 'Approvals and gates' settings are configured per stage and allow you to add pre-deployment and post-deployment approvals, as well as gates such as query-based checks or Azure Monitor alerts. Pre-deployment approvals are the built-in mechanism to pause the pipeline before a stage runs, ensuring authorized reviewers approve the release before it reaches environments like Staging and Production.

  • ✗

    Configure branch policy on the release branch to require approvals.

    Why it's wrong here

    Branch policies in Azure Repos govern pull request workflows and control when code is allowed to merge into a branch. They have no effect on release pipeline execution or stage-level deployment approvals, so configuring a branch policy cannot insert manual sign-off into a release pipeline.

  • ✗

    Add a 'Manual Validation' task in the YAML pipeline.

    Why it's wrong here

    Azure DevOps does not have a built-in 'Manual Validation' task for YAML pipelines; instead, YAML pipelines use the `approvals` keyword defined on the environment to require manual approval before a job runs. Adding a nonexistent task would not provide the required gating, and the scenario's stage-based terminology indicates a classic release pipeline.

  • ✓

    Add a pre-deployment approval gate to the Staging and Production stages.

    Why this is correct

    Pre-deployment approval gates on the Staging and Production stages are the correct way to pause the release before those specific deployments begin, ensuring sequential control and human sign-off. This directly matches the requirement to gate deployments to later environments, making it a valid approach alongside configuring approval settings generally in the release pipeline.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

Courseiva writes every AZ-400 question from scratch — 696 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

8 more ways this is tested on AZ-400

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You have a multi-stage YAML pipeline that deploys to multiple environments. You want to enforce that a manual approval is required before deploying to the production environment, but not for other environments. How should you configure the pipeline?

hard
  • ✓ A.Create an environment named 'Production', add an approval check, and reference the environment in the deployment job.
  • B.Set a pipeline-level approval check that applies to all stages.
  • C.Add an approval gate on the 'Production' stage in the pipeline settings.
  • D.Configure branch policy on the main branch to require approval for all changes.

Why A: Azure Pipelines allows you to add an approval check on a specific environment. By creating an environment named 'Production' and attaching an approval check to it, any deployment job that references that environment will require manual approval before proceeding. This ensures that only the production deployment is gated, while other environments deploy automatically.

Variation 2. You are designing a release pipeline that deploys to multiple environments (dev, test, prod) sequentially. You need to require manual approval before deploying to prod. The approver should be able to review the changes and approve or reject. Which feature should you use?

hard
  • ✓ A.Pre-deployment conditions.
  • B.Environment checks.
  • C.Approval gates.
  • D.Manual intervention task.

Why A: In Azure DevOps release pipelines, to require manual approval before deploying to a specific stage, you configure the pre-deployment conditions of that stage, specifically assigning pre-deployment approvers. These approvers can review the changes and then approve or reject the deployment. This satisfies the requirement directly.

Variation 3. Your Azure Pipelines release pipeline deploys to multiple stages. You need to implement a manual approval gate that requires two specific users to approve before deployment proceeds to production. The approval should expire after 8 hours. Which configuration should you use?

hard
  • ✓ A.Pre-deployment conditions: Add approvers (user1, user2) with 'All' policy and set timeout to 480 minutes
  • B.Pre-deployment conditions: Add approvers (user1, user2) with 'Any one' policy
  • C.Pre-deployment conditions: Add approvers (user1, user2) with 'All' policy and set 'Allow deployment without approval' to true
  • D.Post-deployment conditions: Add approvers (team) with 'All' policy

Why A: It configures a pre-deployment approval gate requiring both user1 and user2 to approve (the 'All' policy) before the production stage proceeds, and sets the timeout to 480 minutes (8 hours) to expire the approval request. This matches the requirement for two specific users to approve and an 8-hour expiration.

Variation 4. You have an Azure DevOps pipeline that deploys to multiple environments. You need to ensure that approvals are required before production deployment. Which pipeline configuration should you use?

easy
  • A.Set the pipeline trigger to 'Manual' only
  • B.Add a 'Manual Intervention' task in the pipeline
  • C.Configure branch policies on the main branch
  • ✓ D.Define an environment with required approvers for the production stage

Why D: Azure DevOps environments allow you to define required approvers for a specific stage (e.g., production). When a pipeline deploys to that environment, it pauses and waits for manual approval before proceeding, ensuring that production deployments are gated by authorized personnel.

Variation 5. You are configuring a release pipeline that deploys to multiple environments. You want to automate the deployment to the staging environment only if the build succeeds, and then require manual approval before deploying to production. Which strategy should you use?

medium
  • ✓ A.Define an environment with approvals required for the production stage.
  • B.Use deployment gates in the production stage to check for manual intervention.
  • C.Use a classic release pipeline with pre-deployment approvals.
  • D.Configure a branch policy on the main branch to require approval for pull requests.

Why A: Azure Pipelines allows you to define environments with explicit approval checks. By adding a manual approval gate on the production environment stage, the pipeline will automatically deploy to staging after a successful build, but pause before production until an authorized user approves the release. This directly meets the requirement for automated staging deployment and manual production approval.

Variation 6. Your team is adopting Azure Pipelines for a new project. You need to ensure that only authorized users can approve releases to production. Which two methods can you use to implement approval checks?

medium
  • ✓ A.Configure pre-deployment approvals on the Production environment.
  • B.Use Deployment Gates with a manual approval gate.
  • ✓ C.Set the 'Required approvers' field on the environment to a specific user or group.
  • D.Add a Manual Intervention task in the release pipeline.
  • E.Add an Approval Check to the agent pool.

Why A: Pre-deployment approvals on the Production environment (Option A) allow you to require one or more users or groups to approve a release before it is deployed to that environment. Similarly, setting the 'Required approvers' field on the environment (Option C) specifies the users or groups that must approve the deployment, which is another native Azure Pipelines approval mechanism. Both enforce authorization at the environment level, ensuring only designated approvers can promote a release to production.

Variation 7. You are configuring a release pipeline in Azure DevOps to deploy to multiple environments (dev, test, prod). You need to ensure that the production deployment requires manual approval from the release manager. What should you configure?

easy
  • ✓ A.Set pre-deployment approvals on the production stage.
  • B.Add a manual intervention task before the production deployment.
  • C.Set post-deployment approvals on the test stage.
  • D.Use a condition on the production stage to check a variable.

Why A: Pre-deployment approvals on the production stage enforce manual sign-off before any deployment to that environment begins. This ensures the release manager must explicitly approve the deployment, meeting the requirement for manual approval on production. Azure DevOps stages support pre-deployment and post-deployment approval gates, with pre-deployment being the correct choice for controlling when a stage starts.

Variation 8. You have a multi-stage YAML pipeline that deploys to Azure App Service. The deployment to the production stage should only proceed if a manual approval is granted. How should you configure this?

medium
  • A.Use deployment gates with Azure Monitor metrics
  • B.Configure branch policies on the main branch
  • C.Add a pipeline decorator to require sign-off
  • ✓ D.Add an approval check on the production environment

Why D: Azure Pipelines supports approval checks on environments, which allow you to require manual approval before a deployment proceeds to a specific stage. By adding an approval check on the production environment, the pipeline will pause at that stage until an authorized user grants approval, meeting the requirement for manual sign-off before production deployment.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.