← Back to Article List         
Configure an Azure Resource Manager Service Connection

Configure an Azure Resource Manager Service Connection

Published on 08 Oct 2026     6 min read Azure DevOps
Service Connections

How to Configure an Azure Resource Manager Service Connection in Azure DevOps

1. What is an Azure Resource Manager Service Connection?

An Azure Resource Manager (ARM) Service Connection allows Azure DevOps Pipelines to securely authenticate to Microsoft Azure and deploy or manage resources such as:

  • Azure App Service

  • Azure Virtual Machines

  • Azure Container Apps

  • Azure Kubernetes Service (AKS)

  • Azure Resource Groups

  • Azure Storage Accounts

For example, if you want to deploy an ASP.NET Core Web API to Azure App Service, you configure an ARM Service Connection and reference it in your YAML pipeline.

2. Prerequisites

Before configuring the connection, ensure you have:

Requirement

Purpose

Azure DevOps Organization

Hosts the pipeline

Azure DevOps Project

Contains the Service Connection

Azure Subscription

Contains the target resources

Azure permissions

Allow creation and authorization of the connection identity

Azure App Service

Deployment destination, if deploying a web application

For automatic workload identity federation setup, you also need sufficient Microsoft Entra ID and Azure RBAC permissions. The exact permissions depend on your organization's policies.

3. Step-by-step configuration

Connecting Azure to Azure DevOps with Federated Credentials and Service Connections
 
 
 

Step 1 – Open Service Connections

  1. Sign in to Azure DevOps.

  2. Select your organization and project.

  3. Open Project Settings.

  4. Under Pipelines, select Service connections.

  5. Click New service connection.

 
Troubleshoot Azure Resource Manager service connections - Azure Pipelines | Microsoft Learn
 
 
 

Step 2 – Select Azure Resource Manager

Select Azure Resource Manager from the available connection types and click Next.

 
Use an Azure Resource Manager service connection - Azure Pipelines | Microsoft Learn
 
 
 

Step 3 – Choose authentication

Select Workload identity federation (automatic) where available.

This is the recommended method because it avoids storing long-lived client secrets.

Alternatives include manually configured workload identity federation and service principal authentication.

Step 4 – Select subscription and scope

Configure the Azure resources the connection will access.

Example:

Field

Example

Scope Level

Subscription

Subscription

MyAzureSubscription

Resource Group

rg-jntech-prod

Service Connection Name

sc-azure-prod

Description

Production App Service Deployment

You can choose resource-group scope where supported to limit access to a specific resource group.

Step 5 – Configure pipeline permissions

For production, leave Grant access permission to all pipelines unchecked.

This allows you to authorize individual pipelines instead of giving every pipeline access.

Step 6 – Save the connection

Click Save or Save and verify, depending on the interface.

Azure DevOps creates or configures the identity and federation trust, subject to the selected authentication method and your permissions.

Step 7 – Verify permissions

Check that the Service Connection's identity has the necessary Azure RBAC role on the target resource or resource group.

For example, a deployment identity might be assigned Website Contributor at the appropriate scope for App Service operations, although the exact role required depends on the task.

 

4. How does authentication work internally?

Azure DevOps Pipeline
         |
         v
ARM Service Connection
         |
         v
Workload Identity Federation
         |
         v
Microsoft Entra ID
         |
         | Validates federated identity
         | Issues Azure access token
         v
Azure Resource Manager
         |
         | Checks RBAC permissions
         v
Azure App Service
         |
         v
ASP.NET Core Application Deployed

The Service Connection defines how Azure DevOps authenticates. Azure RBAC determines which operations are permitted.

5. Using the Service Connection in YAML

Suppose you created:

  • Service Connection: sc-azure-prod

  • Azure App Service: jntech-api-prod

You can reference it in your deployment task.

- task: AzureWebApp@1
  displayName: 'Deploy ASP.NET Core Web API'
  inputs:
    azureSubscription: 'sc-azure-prod'
    appType: 'webApp'
    appName: 'jntech-api-prod'
    package: '$(Pipeline.Workspace)/drop/**/*.zip'

Explanation:

Property

Description

AzureWebApp@1

Azure App Service deployment task

azureSubscription

ARM Service Connection name

appType

Azure App Service type

appName

Target App Service

package

Published application package

The package must already have been downloaded or generated at the specified path.

The important configuration is:

azureSubscription: 'sc-azure-prod'

Azure Pipelines uses this connection to authenticate to Azure when executing the deployment task.

 

6. Configuring Service Connections for multiple environments

In enterprise projects, it is common to configure separate Service Connections.

Environment

Connection

Target

Dev

sc-azure-dev

Development App Service

SIT

sc-azure-sit

SIT App Service

UAT

sc-azure-uat

UAT App Service

Production

sc-azure-prod

Production App Service

                 Build Artifact
                       |
                       v
              DEV Service Connection
                       |
                       v
                  DEV App
                       |
                       v
              SIT Service Connection
                       |
                       v
                  SIT App
                       |
                       v
              UAT Service Connection
                       |
                       v
                  UAT App
                       |
                       v
               Production Approval
                       |
                       v
              PROD Service Connection
                       |
                       v
                Production App

Separate connections help isolate permissions and prevent non-production pipelines from gaining unnecessary access to production resources.

7. Common errors

Error

Cause

Solution

Service Connection not found

Incorrect connection name

Check YAML and connection name

Pipeline not authorized

Pipeline permission missing

Authorize the pipeline

Authorization failed

Insufficient Azure RBAC permissions

Assign the required role

Authentication failed

Federation trust or credentials are invalid

Check identity configuration

Subscription not visible

Insufficient Azure permissions

Verify subscription access

8. Interview questions and answers

Q1. What authentication method is recommended for an ARM Service Connection?

Workload Identity Federation is recommended because it supports authentication without storing long-lived client secrets.

Q2. What is the difference between automatic and manual Workload Identity Federation?

Automatic configuration lets Azure DevOps create and configure the necessary identity and federation settings when permissions allow.

Manual configuration requires you to configure the Microsoft Entra application or managed identity, federated credential, and Azure RBAC permissions yourself.

Q3. Can one ARM Service Connection access multiple Azure resources?

Yes. It can access resources within the identity's authorized scope, provided it has the necessary Azure RBAC permissions.

Q4. How do you restrict production deployment access?

Use a dedicated Production Service Connection, restrict pipeline authorization, assign minimum Azure RBAC permissions, and configure approval checks.

Q5. Does creating a Service Connection automatically deploy an application?

No. The connection provides authentication configuration. You must create a deployment pipeline and reference the Service Connection in the relevant task.

9. Interview-ready answer

To configure an Azure Resource Manager Service Connection, I navigate to Azure DevOps → Project Settings → Service connections → New service connection.

I select Azure Resource Manager and choose Workload Identity Federation as the authentication method. Next, I select the Azure subscription and required resource scope, provide a connection name, and save it.

I ensure the connection identity has the necessary Azure RBAC permissions and authorize the required pipelines.

Finally, I reference the Service Connection name in the YAML deployment task using the azureSubscription property.

For production, I prefer a separate Service Connection with restricted access and deployment approvals.

Key point: Creating the Service Connection establishes the authentication configuration; assigning Azure RBAC permissions and authorizing pipeline usage are separate security controls.

For further reference: Microsoft Learn – Connect Azure Pipelines to Azure.