← Back to Article List         
Azure DevOps – Integrating Azure Key Vault with Azure Pipelines

Azure DevOps – Integrating Azure Key Vault with Azure Pipelines

Published on 08 Oct 2026     7 min read Azure DevOps
Variables, Secrets

1. What is Azure Key Vault Integration?

Azure Key Vault integration allows Azure DevOps Pipelines to securely retrieve sensitive information from Azure Key Vault during build or deployment.

Azure Key Vault can store:

  • Database passwords and connection strings

  • API keys and access tokens

  • JWT signing secrets

  • Certificates and cryptographic keys

Instead of hardcoding these values in azure-pipelines.yml, we store them in Azure Key Vault and retrieve them securely when needed.

Main purpose: Protect application secrets and manage them centrally without exposing credentials in source code or pipeline configuration.

2. How does it work?

Azure Key Vault
   |
   | Stores:
   | - DbPassword
   | - ApiKey
   | - JwtSecret
   |
   v
Azure Service Connection
   |
   | Authenticates Pipeline
   v
Azure DevOps Pipeline
   |
   | AzureKeyVault@2 Task
   v
Retrieve Required Secrets
   |
   v
Deploy ASP.NET Core Web API
   |
   v
Configure Application Securely

The Azure Service Connection provides an identity for authentication. Azure Key Vault permissions determine which secrets that identity can access.

There are two common integration methods:

  1. AzureKeyVault@2 task: Retrieve secrets directly within a YAML pipeline.

  2. Key Vault-linked Variable Group: Link a Variable Group to Azure Key Vault and use its secrets across pipelines.

 

3. Method 1 – Using AzureKeyVault@2 Task

This is a straightforward way to retrieve secrets directly in a YAML pipeline.

Step 1 – Create Azure Key Vault

In the Azure Portal:

  1. Search for Key Vaults.

  2. Click Create.

  3. Select Subscription and Resource Group.

  4. Enter a Key Vault name, for example kv-employee-prod.

  5. Select a region and create the vault.

Step 2 – Add Secrets

Navigate to:

Azure Portal → Key Vault → Objects → Secrets → Generate/Import

Create the following example secrets:

Secret name

Example value

DbPassword

A secure database password

ApiKey

An application API key

JwtSecret

A strong JWT signing secret

The actual secret values remain stored in Key Vault.

Step 3 – Create an Azure Service Connection

Navigate to:

Azure DevOps → Project Settings → Service connections → New service connection

Choose:

  • Connection type: Azure Resource Manager

  • Authentication: Workload identity federation (recommended)

  • Azure subscription: The subscription containing Key Vault

  • Connection name: Production-ServiceConnection

This service connection allows Azure Pipelines to authenticate to Azure without storing a long-lived client secret.

Step 4 – Grant Key Vault Access

Open your Key Vault in the Azure Portal.

For a vault using Azure RBAC:

  1. Open Access control (IAM).

  2. Click Add role assignment.

  3. Select Key Vault Secrets User.

  4. Assign the role to the identity used by your service connection.

  5. Save the assignment.

For a vault using access policies, grant the identity Get and List secret permissions instead.

Also ensure the pipeline agent has network access to the vault.

Microsoft Learn
+1

 

Step 5 – Add AzureKeyVault@2 to YAML

trigger:
- main

pool:
  vmImage: 'windows-latest'

steps:
- task: AzureKeyVault@2
  displayName: 'Retrieve secrets from Key Vault'
  inputs:
    azureSubscription: 'Production-ServiceConnection'
    KeyVaultName: 'kv-employee-prod'
    SecretsFilter: 'DbPassword,ApiKey,JwtSecret'
    RunAsPreJob: false

- task: PowerShell@2
  displayName: 'Use secrets securely'
  inputs:
    targetType: 'inline'
    script: |
      Write-Host "Secrets are available to this task"
  env:
    DB_PASSWORD: $(DbPassword)
    API_KEY: $(ApiKey)
    JWT_SECRET: $(JwtSecret)

Important YAML properties

Property

Purpose

azureSubscription

Name of the Azure service connection

KeyVaultName

Azure Key Vault name

SecretsFilter

Comma-separated secret names; * retrieves all

RunAsPreJob

If true, makes secrets available to all tasks in the job

Once the task succeeds, the retrieved values become secret pipeline variables for subsequent tasks in that job. They should be explicitly mapped to environment variables when scripts need them.

Microsoft Learn
+1

 

 

4. Method 2 – Using Key Vault-linked Variable Groups

This method is useful when multiple pipelines need the same secrets.

Steps

  1. Open Azure DevOps → Pipelines → Library.

  2. Click + Variable group.

  3. Enter the name PROD-Secrets.

  4. Enable Link secrets from an Azure Key Vault as variables.

  5. Select your Azure service connection.

  6. Select kv-employee-prod.

  7. Click Add and select the required secrets.

  8. Save and authorize the Variable Group for the pipeline.

YAML Example

variables:
- group: PROD-Secrets

steps:
- task: PowerShell@2
  inputs:
    targetType: 'inline'
    script: |
      Write-Host "Production secrets are available"
  env:
    DB_PASSWORD: $(DbPassword)
    API_KEY: $(ApiKey)

Important: Variable Groups map selected secret names rather than copying secret values into the group. Updated values of existing mapped secrets are retrieved at runtime. Newly added secret names must be mapped manually.

Microsoft Learn
+1

 

 

5. AzureKeyVault@2 vs Key Vault-linked Variable Group

Feature

AzureKeyVault@2

Variable Group

Secret retrieval

Directly from a pipeline task

Through a linked group

Configuration

YAML

Azure DevOps Library

Reusability

Configure task where needed

Shared across pipelines

Secret selection

SecretsFilter

Select secrets in Library

Best suited for

Explicit secret retrieval in a job

Centralized shared secrets

Both methods are valid. Choose based on your pipeline architecture and access-control requirements.

 

6. Real Project Example – ASP.NET Core Web API

Suppose you deploy an Employee Web API to four environments.

Azure DevOps CI Pipeline
         |
         v
Build ASP.NET Core Web API
         |
         v
Publish Artifact
         |
         v
DEV Deployment
   → DEV Key Vault
         |
         v
SIT Deployment
   → SIT Key Vault
         |
         v
UAT Deployment
   → UAT Key Vault
         |
         v
Production Approval
         |
         v
PROD Deployment
   → Production Key Vault

Each deployment stage uses a separate Key Vault or appropriately isolated secrets.

The application can receive its configuration through secure App Service settings or Key Vault references.

Important distinction: Retrieving a secret into Azure Pipelines does not automatically configure the deployed ASP.NET Core application. The deployment process must pass it securely to the application, or the application must access Key Vault directly through Managed Identity.

 

7. Common Issues and Troubleshooting

Error

Possible cause

Solution

403 Forbidden

Missing Key Vault permissions

Grant Secrets User or required access-policy permissions

Secret not found

Incorrect secret name

Verify name and SecretsFilter

Service connection error

Missing authorization

Authorize the pipeline to use the connection

Network access denied

Key Vault firewall/private endpoint restrictions

Configure permitted network access

Variable is empty

Secret unavailable or not mapped

Check retrieval task, scope, and variable name

For private Key Vaults, a self-hosted agent with appropriate private network connectivity is often necessary.

Microsoft Learn
+1

 

 

8. Important Interview Questions

Q1. How does Azure Pipelines authenticate to Azure Key Vault?

Through an Azure Resource Manager service connection, preferably using workload identity federation.

Q2. Which task retrieves secrets from Azure Key Vault?

AzureKeyVault@2.

Q3. Can multiple pipelines use the same Key Vault secrets?

Yes. Pipelines can access authorized secrets directly or through a Key Vault-linked Variable Group.

Q4. What happens when a secret is rotated in Azure Key Vault?

Subsequent pipeline runs can retrieve the latest enabled secret version. Already-running applications may need configuration refresh or restart depending on how they consume the secret.

Q5. How do you protect Production secrets?

Use separate Key Vaults, least-privilege RBAC, restricted service connections, pipeline permissions, and Production deployment approvals.

 

9. Interview-ready Answer

"In Azure DevOps, we integrate Azure Key Vault with Azure Pipelines using an Azure Resource Manager service connection.

First, we create a Key Vault and store sensitive information such as database passwords, connection strings, and API keys.

Next, we configure a service connection using workload identity federation and grant the required Key Vault permissions.

In our YAML pipeline, we use the AzureKeyVault@2 task to retrieve the required secrets securely. Alternatively, we can link Azure Key Vault to a Variable Group and share secrets across pipelines.

For DEV, SIT, UAT, and Production, we maintain separate secret configurations and restrict Production access.

This approach eliminates hardcoded secrets and improves security and maintainability."

Key takeaway: Azure Key Vault stores secrets, the Azure Service Connection authenticates the pipeline, and AzureKeyVault@2 or a linked Variable Group makes authorized secrets available during execution.