How to Configure an Azure Resource Manager Service Connection in Azure DevOps
1. What is an Azure Resource Manager Service Connection?
An Azure Resource Manager (ARM) Service Connection allows Azure DevOps Pipelines to securely authenticate to Microsoft Azure and deploy or manage resources such as:
-
Azure App Service
-
Azure Virtual Machines
-
Azure Container Apps
-
Azure Kubernetes Service (AKS)
-
Azure Resource Groups
-
Azure Storage Accounts
For example, if you want to deploy an ASP.NET Core Web API to Azure App Service, you configure an ARM Service Connection and reference it in your YAML pipeline.
2. Prerequisites
Before configuring the connection, ensure you have:
|
Requirement |
Purpose |
|---|---|
|
Azure DevOps Organization |
Hosts the pipeline |
|
Azure DevOps Project |
Contains the Service Connection |
|
Azure Subscription |
Contains the target resources |
|
Azure permissions |
Allow creation and authorization of the connection identity |
|
Azure App Service |
Deployment destination, if deploying a web application |
For automatic workload identity federation setup, you also need sufficient Microsoft Entra ID and Azure RBAC permissions. The exact permissions depend on your organization's policies.
3. Step-by-step configuration
Step 1 – Open Service Connections
-
Sign in to Azure DevOps.
-
Select your organization and project.
-
Open Project Settings.
-
Under Pipelines, select Service connections.
-
Click New service connection.
Step 2 – Select Azure Resource Manager
Select Azure Resource Manager from the available connection types and click Next.
Step 3 – Choose authentication
Select Workload identity federation (automatic) where available.
This is the recommended method because it avoids storing long-lived client secrets.
Alternatives include manually configured workload identity federation and service principal authentication.
Step 4 – Select subscription and scope
Configure the Azure resources the connection will access.
Example:
|
Field |
Example |
|---|---|
|
Scope Level |
Subscription |
|
Subscription |
MyAzureSubscription |
|
Resource Group |
rg-jntech-prod |
|
Service Connection Name |
sc-azure-prod |
|
Description |
Production App Service Deployment |
You can choose resource-group scope where supported to limit access to a specific resource group.
Step 5 – Configure pipeline permissions
For production, leave Grant access permission to all pipelines unchecked.
This allows you to authorize individual pipelines instead of giving every pipeline access.
Step 6 – Save the connection
Click Save or Save and verify, depending on the interface.
Azure DevOps creates or configures the identity and federation trust, subject to the selected authentication method and your permissions.
Step 7 – Verify permissions
Check that the Service Connection's identity has the necessary Azure RBAC role on the target resource or resource group.
For example, a deployment identity might be assigned Website Contributor at the appropriate scope for App Service operations, although the exact role required depends on the task.
4. How does authentication work internally?
Azure DevOps Pipeline
|
v
ARM Service Connection
|
v
Workload Identity Federation
|
v
Microsoft Entra ID
|
| Validates federated identity
| Issues Azure access token
v
Azure Resource Manager
|
| Checks RBAC permissions
v
Azure App Service
|
v
ASP.NET Core Application Deployed
The Service Connection defines how Azure DevOps authenticates. Azure RBAC determines which operations are permitted.
5. Using the Service Connection in YAML
Suppose you created:
-
Service Connection:
sc-azure-prod -
Azure App Service:
jntech-api-prod
You can reference it in your deployment task.
- task: AzureWebApp@1
displayName: 'Deploy ASP.NET Core Web API'
inputs:
azureSubscription: 'sc-azure-prod'
appType: 'webApp'
appName: 'jntech-api-prod'
package: '$(Pipeline.Workspace)/drop/**/*.zip'
Explanation:
|
Property |
Description |
|---|---|
|
|
Azure App Service deployment task |
|
|
ARM Service Connection name |
|
|
Azure App Service type |
|
|
Target App Service |
|
|
Published application package |
The package must already have been downloaded or generated at the specified path.
The important configuration is:
azureSubscription: 'sc-azure-prod'
Azure Pipelines uses this connection to authenticate to Azure when executing the deployment task.
6. Configuring Service Connections for multiple environments
In enterprise projects, it is common to configure separate Service Connections.
|
Environment |
Connection |
Target |
|---|---|---|
|
Dev |
|
Development App Service |
|
SIT |
|
SIT App Service |
|
UAT |
|
UAT App Service |
|
Production |
|
Production App Service |
Build Artifact
|
v
DEV Service Connection
|
v
DEV App
|
v
SIT Service Connection
|
v
SIT App
|
v
UAT Service Connection
|
v
UAT App
|
v
Production Approval
|
v
PROD Service Connection
|
v
Production App
Separate connections help isolate permissions and prevent non-production pipelines from gaining unnecessary access to production resources.
7. Common errors
|
Error |
Cause |
Solution |
|---|---|---|
|
Service Connection not found |
Incorrect connection name |
Check YAML and connection name |
|
Pipeline not authorized |
Pipeline permission missing |
Authorize the pipeline |
|
Authorization failed |
Insufficient Azure RBAC permissions |
Assign the required role |
|
Authentication failed |
Federation trust or credentials are invalid |
Check identity configuration |
|
Subscription not visible |
Insufficient Azure permissions |
Verify subscription access |
8. Interview questions and answers
Q1. What authentication method is recommended for an ARM Service Connection?
Workload Identity Federation is recommended because it supports authentication without storing long-lived client secrets.
Q2. What is the difference between automatic and manual Workload Identity Federation?
Automatic configuration lets Azure DevOps create and configure the necessary identity and federation settings when permissions allow.
Manual configuration requires you to configure the Microsoft Entra application or managed identity, federated credential, and Azure RBAC permissions yourself.
Q3. Can one ARM Service Connection access multiple Azure resources?
Yes. It can access resources within the identity's authorized scope, provided it has the necessary Azure RBAC permissions.
Q4. How do you restrict production deployment access?
Use a dedicated Production Service Connection, restrict pipeline authorization, assign minimum Azure RBAC permissions, and configure approval checks.
Q5. Does creating a Service Connection automatically deploy an application?
No. The connection provides authentication configuration. You must create a deployment pipeline and reference the Service Connection in the relevant task.
9. Interview-ready answer
To configure an Azure Resource Manager Service Connection, I navigate to Azure DevOps → Project Settings → Service connections → New service connection.
I select Azure Resource Manager and choose Workload Identity Federation as the authentication method. Next, I select the Azure subscription and required resource scope, provide a connection name, and save it.
I ensure the connection identity has the necessary Azure RBAC permissions and authorize the required pipelines.
Finally, I reference the Service Connection name in the YAML deployment task using the azureSubscription property.
For production, I prefer a separate Service Connection with restricted access and deployment approvals.
Key point: Creating the Service Connection establishes the authentication configuration; assigning Azure RBAC permissions and authorizing pipeline usage are separate security controls.
For further reference: Microsoft Learn – Connect Azure Pipelines to Azure.