Using NuGetAuthenticate to Authenticate a Feed Without Managing PATs
Your build pipeline uses the 'NuGetCommand@2' task to restore NuGet packages. You want to use packages from an Azure Artifacts feed that requires authentication. How should you configure the pipeline to authenticate with the feed?
Quick Answer
Adding a NuGetAuthenticate@1 task immediately before the NuGetCommand@2 restore step is the supported way to authenticate against an Azure Artifacts feed — it automatically acquires credentials through the built-in Azure Artifacts credential provider using the pipeline's own identity, so there's no personal access token to create, store, or rotate manually.
⚠ Common exam trap
Watch out — candidates often confuse service connections (which are used for external services like GitHub or generic endpoints) with the built-in Azure Artifacts authentication, leading them to select Option B, but Azure Artifacts feeds do not require a service connection because authentication is handled automatically via the pipeline's identity and the 'NuGetAuthenticate@1' task.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a 'NuGetAuthenticate@1' task before the NuGet restore task.
The 'NuGetAuthenticate@1' task is the correct way to authenticate with Azure Artifacts feeds in a pipeline because it automatically handles credential acquisition using the built-in Azure Artifacts credential provider. It works without needing to store or manage Personal Access Tokens (PATs) manually, and it integrates seamlessly with the pipeline's identity (e.g., the project collection build service). This task must be placed before the 'NuGetCommand@2' restore task to ensure the credentials are available for package restoration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the Personal Access Token (PAT) in a variable and use it in the NuGet config.
Why it's wrong here
A PAT stored in a plain variable is not automatically masked unless explicitly marked secret, and it expires, breaking builds. PATs suit local developer authentication or one-off scripts; pipeline authentication to Azure Artifacts feeds should use the built-in credential provider via the NuGetAuthenticate task or a service connection.
- ✗
Create an Azure Artifacts service connection and select it in the NuGet task.
Why it's wrong here
The NuGetCommand@2 task has no service connection input for feed authentication; it authenticates through the NuGet credential provider, configured by the NuGetAuthenticate task. Service connections suit tasks that expose a connectedServiceName input, such as Docker or Azure CLI tasks, not NuGet restore.
- ✓
Add a 'NuGetAuthenticate@1' task before the NuGet restore task.
Why this is correct
NuGetAuthenticate@1 injects credentials for Azure Artifacts feeds into the NuGet configuration at runtime, authenticating via the pipeline's service connection or Microsoft Entra ID identity. Placing it before NuGetCommand@2 satisfies the stem's requirement that the authenticated feed restore succeeds without hard-coded credentials in nuget.config.
- ✗
Install the NuGet credential provider on the agent manually.
Why it's wrong here
Microsoft-hosted agents already include the NuGet credential provider, so manual installation is unnecessary and unmaintainable across ephemeral agents. Manual installation suits self-hosted agents with restricted images lacking the provider, but the supported approach is invoking NuGetAuthenticate to configure the existing provider.
Go deeper
Related to this question
Learn chapter
Designing a Build Pipeline
Key term
Azure Artifacts
Azure Artifacts is a service within Azure DevOps that allows teams to create, host, and share packages like NuGet, npm, Maven, and Python, making software dependencies easier to manage across projects.
Key term
Build pipeline
A build pipeline is an automated sequence of steps that compiles source code into a deployable artifact, running tests and checks along the way.
About these practice questions
One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-400
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You have a YAML pipeline that builds a Java project using Maven. The pipeline uses a private artifact feed in Azure Artifacts. You need to authenticate to the feed from the pipeline. Which authentication method should you use?
medium- A.Use the 'PipAuthenticate' task with a pip.conf file.
- B.Use the 'npmAuthenticate' task with a .npmrc file.
- ✓ C.Use the 'MavenAuthenticate' task with a settings.xml file.
- D.Use the 'NuGetAuthenticate' task with a nuget.config file.
Why C: The 'MavenAuthenticate' task is specifically designed to authenticate Maven builds against Azure Artifacts feeds. It injects credentials into a settings.xml file, which Maven uses to resolve dependencies from the private feed. This task handles the OAuth token exchange required for Azure DevOps authentication.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.