Why a Correctly Permissioned Service Principal Still Gets Key Vault Access Denied
You are designing a release pipeline that deploys a web app to Azure App Service. You need to ensure that configuration secrets (e.g., database connection strings) are not stored in the pipeline YAML file. Which approach should you use?
⚠ Common exam trap
The trap is that candidates often choose Option D (secret pipeline variables) because they mask output in logs, but they fail to realize that the secret value is still stored in the pipeline definition (not in YAML, but in Azure DevOps) and can be viewed by users with access to the pipeline settings or exported via API. Key Vault variable groups provide better security through centralized secret management, permissions, and audit logging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an Azure Key Vault variable group linked to the pipeline.
Azure Key Vault variable groups allow you to securely reference secrets stored in Azure Key Vault from within a pipeline without exposing them in the YAML file. The pipeline retrieves the secrets at runtime via a linked service connection, ensuring they never appear in source control or pipeline logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Define the secrets as agent-scoped variables in the release pipeline.
Why it's wrong here
Defining secrets as agent-scoped variables stores them in plain text on the agent, making them readable by any process on that machine and visible in build logs. They are not encrypted at rest or in transit, and anyone with pipeline edit permissions can retrieve them, so this approach offers no real protection compared to Azure Key Vault.
- ✗
Hardcode the secrets in the App Service configuration and reference them in the pipeline.
Why it's wrong here
Hardcoding secrets in the App Service configuration embeds them as plain-text settings in the Azure resource, exposing them to anyone with read access to the app's configuration or logs. Referencing these from the pipeline spreads the secret into the release definitions and does not address the insecure storage; instead, use Key Vault references to keep secrets out of both the pipeline and App Service settings.
- ✓
Use an Azure Key Vault variable group linked to the pipeline.
Why this is correct
Linking an Azure Key Vault variable group to the release pipeline is the recommended approach because secrets are never stored in the pipeline definition or on the agent. Instead, Azure DevOps securely retrieves the latest secret values from Key Vault at runtime using the configured ARM service connection, which in turn uses a service principal or managed identity. This enables centralized secret management with fine-grained access policies, automatic rotation support, and eliminates the risk of exposing secrets in logs, version control, or build artifacts.
- ✗
Store the secrets as pipeline variables and mark them as 'Secret'.
Why it's wrong here
Storing secrets as pipeline variables and marking them as 'Secret' does provide some protection—Azure DevOps encrypts such variables with AES-128 and masks them in the logs—but it is not a true secret management solution. Anyone with pipeline edit permissions can still read the variable value, and the secrets are not inherited from or linked to your Key Vault, so there is no central access control or lifecycle management. Moreover, secrets can leak if a task explicitly echoes the variable, if debug mode is enabled, or if the variable is passed to an untrusted process, making this approach less secure than a Key Vault variable group.
Go deeper
Related to this question
Learn chapter
Implementing and Managing Source Control
Key term
Pipeline
A pipeline is an automated series of steps that takes code from development to production, ensuring quality and speed.
Key term
Service connection
A service connection in Azure DevOps is a secure, configurable link that allows your pipelines to authenticate and interact with external services like Azure, GitHub, or on-premises servers.
About these practice questions
Courseiva writes every AZ-400 question from scratch — 696 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-400
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your company uses Azure Key Vault to store secrets. Which TWO actions should you take to ensure secure access? (Select TWO.)
medium- ✓ A.Restrict access using Key Vault access policies
- ✓ B.Use managed identities to authenticate applications
- C.Enable HTTP access for performance
- D.Disable audit logging to reduce exposure
- E.Enable soft-delete to recover deleted secrets
Why A: Restricting access using Key Vault access policies (Option A) is correct because Azure Key Vault uses a granular permission model where you assign specific permissions (e.g., GET, LIST, SET) to individual security principals (users, groups, or service principals) at the vault level. This ensures that only authorized identities can read or manage secrets, keys, and certificates, following the principle of least privilege. Using managed identities (Option B) is correct because they provide an automatically managed identity in Azure AD for applications to authenticate to Key Vault without storing credentials in code or configuration, eliminating the risk of secret leakage.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.