Three Security Best Practices Every Azure Pipelines Setup Should Follow
Which THREE are valid security best practices for Azure Pipelines? (Choose three.)
Quick Answer
Using variable groups with Key Vault integration for secrets, restricting agent pool creation to a small admin team, and applying the principle of least privilege through granular security groups are the security fundamentals that hold up an Azure Pipelines setup — centralizing secret storage while limiting who can create infrastructure that could be abused.
⚠ Common exam trap
It's easy for candidates to think storing secrets in YAML files is acceptable if the repository is private, but Azure Pipelines explicitly warns against this because secrets can be exposed in pipeline logs, build artifacts, or through source control history.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict agent pool permissions to only necessary users
Option A is correct because restricting agent pool permissions to only necessary users enforces least privilege, preventing unauthorized users from creating or modifying agents that could execute malicious pipeline jobs. Option B is correct because Microsoft Entra ID (formerly Azure AD) provides centralized identity and access control for Azure DevOps, enabling conditional access, MFA, and role-based assignments to secure pipeline access. Option D is correct because variable groups integrated with Azure Key Vault keep secrets out of YAML and pipeline definitions, retrieving them securely at runtime with proper access policies. Option C is not a best practice because storing secrets as plain text in YAML files exposes them to anyone with repository read access and to logs or history. Option E is not a best practice because running build agents on domain controllers violates the principle of least privilege and exposes critical identity infrastructure to pipeline workloads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Restrict agent pool permissions to only necessary users
Why this is correct
Agent pool permissions determine which identities can queue jobs onto agents, so restricting them to necessary users prevents unauthorised pipeline runs and credential exposure on shared agents. This enforces least privilege at the compute boundary, a core Azure Pipelines security control.
- ✓
Use Microsoft Entra ID to control access to pipelines
Why this is correct
Microsoft Entra ID provides the identity plane for Azure DevOps, enforcing conditional access, multifactor authentication and role-based permissions across pipelines. This satisfies the stem's security best-practice constraint by centralising authentication and eliminating local credentials, ensuring only authorised identities trigger or modify pipeline definitions and service connections.
- ✗
Store secrets as plain text in YAML files
Why it's wrong here
Plain-text YAML secrets are readable by anyone with repository or pipeline access and persist in source history, so they cannot be rotated or audited safely. It is tempting because inline variables are quick to author, but secrets belong in Azure Key Vault or secret variables, never committed to YAML.
- ✓
Use variable groups with Azure Key Vault integration for secrets
Why this is correct
Variable groups linked to Azure Key Vault retrieve secrets at runtime rather than storing them in pipeline definitions, so plaintext values never persist in Azure DevOps. This satisfies the requirement to protect credentials used by pipeline tasks.
- ✗
Run build agents on domain controllers
Why it's wrong here
Running build agents on domain controllers violates the separation of duties principle: agents execute untrusted pipeline code, and a compromised agent would inherit directory services privileges, exposing the entire domain. It is tempting because domain controllers centralise authentication and Group Policy, so joining agents to that domain simplifies credential management — but agents belong on isolated, dedicated hosts, never on directory servers.
Go deeper
Related to this question
Learn chapter
Implementing Security and Compliance in Pipelines
Key term
Repository
A repository is a central storage location where software packages, code, or configuration files are kept, managed, and distributed for use by IT systems.
Key term
Azure DevOps
Azure DevOps is a Microsoft service that provides development tools for planning, building, testing, and deploying software applications using automated pipelines and collaboration features.
About these practice questions
One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-400
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE measures should be implemented to protect secrets in Azure Pipelines? (Choose three.)
medium- ✓ A.Restrict which pipelines can access the variable group
- B.Log secret values to pipeline console for debugging
- ✓ C.Use variable groups with locked variables
- ✓ D.Link Azure Key Vault as a variable group
- E.Store secrets in code as environment variables
Why A: Restricting which pipelines can access a variable group ensures that only authorized pipelines can use secrets stored in that group, preventing unauthorized access or accidental exposure. This is a key security measure in Azure Pipelines to enforce the principle of least privilege.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.