Module 1 – Azure DevOps Security Fundamentals
This module introduces the core security concepts required to build secure CI/CD environments using Azure DevOps.
Topics
- Azure DevOps security architecture
- DevSecOps principles
- Secure CI/CD concepts
- Common pipeline security risks
- Security best practices
Module 2 – Secure Project and Repository Design
Learn how to organize Azure DevOps projects and repositories using security-focused design principles.
Topics
- Azure DevOps organization structure
- Project configuration
- Repository management
- Branch strategies
- Protected branches
- Repository access policies
- Secure folder structures
Hands-on Lab
- Creating secure projects
- Configuring repositories
- Implementing branch protection policies
Module 3 – Identity and Access Management
This module focuses on authentication, authorization, and identity management within Azure DevOps.
Topics
- Managed Identity
- Service Principals
- Service Connections
- Agent identities
- Microsoft-hosted agents
- Self-hosted agents
- Least privilege access
Hands-on Lab
- Creating Service Connections
- Configuring Managed Identity
- Securing build agents
Module 4 – Securing Azure Pipelines
Participants will learn how to build secure deployment pipelines using Azure DevOps YAML pipelines.
Topics
- YAML pipeline architecture
- Pipeline templates
- Nested templates
- Pipeline extensibility
- Secure deployment practices
- Approval workflows
- Environment configuration
- Agent pool security
Hands-on Lab
- Building multi-stage pipelines
- Working with reusable templates
Module 5 – Secrets and Credential Management
This module demonstrates how to protect sensitive information throughout the CI/CD lifecycle.
Topics
- Secret variables
- Variable groups
- Secure files
- Azure Key Vault integration
- Certificate management
- Token security
- Credential management
Hands-on Lab
- Connecting Azure Key Vault
- Managing secrets
- Configuring variable groups
Module 6 – Permissions and Security Governance
Learn how to configure permissions, approvals, and governance controls within Azure DevOps.
Topics
- User permissions
- Pipeline permissions
- Repository permissions
- Branch policies
- Approval workflows
- Audit logs
- Security monitoring
- Compliance reporting
Hands-on Lab
- Validating permissions
- Testing pipeline security policies
Module 7 – Building Secure YAML Pipelines
This module focuses on advanced techniques for creating secure, maintainable, and reusable deployment pipelines.
Topics
- Secure parameter handling
- Variable security
- YAML validation
- Queue-time variable restrictions
- Script security
- Log protection
- Secure deployment strategies
- DevSecOps implementation best practices
Hands-on Lab
- Developing secure YAML pipelines
- Pipeline security validation
- End-to-end deployment scenarios
Practical Labs
During the course, participants will complete practical exercises including:
- Creating Azure DevOps projects
- Configuring secure repositories
- Building Azure Pipelines
- Integrating Azure Key Vault
- Managing secrets securely
- Configuring Managed Identities
- Creating Service Connections
- Developing reusable pipeline templates
- Auditing security configurations
- Validating permissions
- Implementing secure deployment workflows
Skills Gained
After completing this course, participants will be able to design, implement, and manage secure Azure DevOps environments that support enterprise DevSecOps initiatives. They will understand how to secure pipelines, repositories, identities, permissions, and deployment processes while protecting sensitive information throughout the software delivery lifecycle.
The practical knowledge gained during this course can be immediately applied to Azure-based development environments, helping organizations strengthen CI/CD security, improve governance, and reduce operational risk.