Azure DevOps pipelines sit on a privileged path between source code and production. They execute untrusted changes, consume package feeds, use service connections, and often hold enough permission to deploy. Securing them means governing the whole path—not merely adding one scan step.
Use this checklist to review an organization or to define the minimum standard for every new project.
Identity and access
- Limit Project Collection Administrator and Build Administrator membership.
- Scope job access tokens to the smallest practical project and resources.
- Use groups and service identities instead of long-lived personal credentials.
- Review who may edit pipelines, queue builds, and bypass checks.
Repositories and pull requests
- Protect main and release branches with required pull requests.
- Require reviewers, comment resolution, and automatic build validation.
- Use required status checks for security decisions and tightly restrict bypass rights.
Credentials and pipeline resources
- Restrict service connections to named pipelines instead of open access.
- Prefer federated or short-lived identity where supported over stored secrets.
- Limit variable-group, environment, agent-pool, and secure-file permissions.
Security testing and enforcement
- Run the relevant mix of SAST, SCA, secrets, container, and IaC scanning.
- Track eligible pipelines as the denominator for coverage—not only pipelines already scanning.
- Evaluate one central policy for monitor-only or fail-build decisions.
Operations and evidence
- Detect configuration drift and provide a controlled repair path.
- Retain an audit trail for enrollments, disables, policy changes, syncs, and emergency actions.
Turn the checklist into continuous control
A spreadsheet can establish a baseline, but it cannot keep the baseline true. Kangl continuously inventories Azure DevOps, manages security-provider and pipeline state, evaluates policy, surfaces drift, repairs configuration, and preserves the evidence behind every operation.

