AZ - 2001 : Implement Security through a Pipeline using Azure DevOps
The AZ-2001: Implement Security Through a Pipeline Using Azure DevOps course prepares you for the Implement Security Through a Pipeline assessment. It focuses on configuring and securing Azure Pipelines with hands-on practice. You'll learn to manage secure access to pipeline resources, validate permissions, set up project and repository structures, extend pipelines, and handle variables and parameters securely. The course also covers managing identities for projects, pipelines, and agents to ensure robust security practices in your DevOps processes.
Instructor
AZ - 2001 : Implement Security through a Pipeline using Azure DevOps Training
Curriculum
Master security implementation in Azure DevOps with AZ-2001: Implement Security through a Pipeline Training. Learn key skills for securing CI/CD pipelines in Azure.
AZ - 2001 : Implement Security through a Pipeline using Azure DevOps
This course prepares you for the assessment on implementing security through a pipeline using Azure DevOps. It covers how to configure and secure Azure Pipelines, including hands-on practice in:
Configuring secure access to pipeline resources
Validating permissions
Setting up project and repository structures
Extending pipelines
Using variables and parameters securely
Managing identities for projects, pipelines, and agents
Audience Profile:
The primary audience for this course includes:
Administrators
Developers
DevOps Engineers
Security Engineers
Security Operations Analysts
Solution Architects
Students
Support Engineers
Prerequisites:
An Azure Subscription (you need to bring your own).
Basic knowledge of Azure DevOps.
Fundamental understanding of security concepts, such as identities and permissions.
Experience using the Azure portal to create resources like Azure Key Vault and manage permissions.
Course Outline:
Module 1: Configure a Project and Repository Structure to Support Secure Pipelines Lessons:
Separate a project into team projects and repositories
Separate secure files between projects
Move the security repository away from a project
Assign project and repository permissions
Organize a project and repository structure
Module 2: Configure Secure Access to Pipeline Resources Lessons:
Identify and mitigate common security threats
Configure pipeline access to specific agent pools
Manage secret variables and variable groups
Secure files and storage
Configure service connections
Manage environments
Secure repositories
Module 3: Manage Identity for Projects, Pipelines, and Agents Lessons:
Configure a Microsoft-hosted pool
Configure agents for projects
Configure agent identities
Configure the scope of a service connection
Convert to a managed identity in Azure DevOps
Module 4: Configure and Validate Permissions Lessons:
Configure and validate user permissions
Configure and validate pipeline permissions
Configure and validate approval and branch checks
Manage and audit permissions in Azure DevOps
Module 5: Extend a Pipeline to Use Multiple Templates Lessons:
Create nested templates
Rewrite the main deployment pipeline
Configure the pipeline and the application to use tokenization
Remove plain text secrets
Restrict agent logging
Identify and conditionally remove script tasks in Azure DevOps
Module 6: Configure Secure Access to Azure Repos from Pipelines Lessons:
Configure pipeline access to packages
Configure credential secrets, and secrets for services
Ensure that the secrets are in the Azure Key Vault
Ensure that secrets aren't in the logs
Module 7: Configure Pipelines to Securely Use Variables and Parameters Lessons:
Ensure that parameters and variables retain their type
Identify and restrict insecure use of parameters and variables
Move parameters into a YAML file that protects their type
Limit variables that can be set at queue time
Validate that mandatory variables are present and set correctly in Azure DevOps
This course prepares you for the assessment on implementing security through a pipeline using Azure DevOps. It covers how to configure and secure Azure Pipelines, including hands-on practice in:
Configuring secure access to pipeline resources
Validating permissions
Setting up project and repository structures
Extending pipelines
Using variables and parameters securely
Managing identities for projects, pipelines, and agents
Audience Profile:
The primary audience for this course includes:
Administrators
Developers
DevOps Engineers
Security Engineers
Security Operations Analysts
Solution Architects
Students
Support Engineers
Prerequisites:
An Azure Subscription (you need to bring your own).
Basic knowledge of Azure DevOps.
Fundamental understanding of security concepts, such as identities and permissions.
Experience using the Azure portal to create resources like Azure Key Vault and manage permissions.
Course Outline:
Module 1: Configure a Project and Repository Structure to Support Secure Pipelines Lessons:
Separate a project into team projects and repositories
Separate secure files between projects
Move the security repository away from a project
Assign project and repository permissions
Organize a project and repository structure
Module 2: Configure Secure Access to Pipeline Resources Lessons:
Identify and mitigate common security threats
Configure pipeline access to specific agent pools
Manage secret variables and variable groups
Secure files and storage
Configure service connections
Manage environments
Secure repositories
Module 3: Manage Identity for Projects, Pipelines, and Agents Lessons:
Configure a Microsoft-hosted pool
Configure agents for projects
Configure agent identities
Configure the scope of a service connection
Convert to a managed identity in Azure DevOps
Module 4: Configure and Validate Permissions Lessons:
Configure and validate user permissions
Configure and validate pipeline permissions
Configure and validate approval and branch checks
Manage and audit permissions in Azure DevOps
Module 5: Extend a Pipeline to Use Multiple Templates Lessons:
Create nested templates
Rewrite the main deployment pipeline
Configure the pipeline and the application to use tokenization
Remove plain text secrets
Restrict agent logging
Identify and conditionally remove script tasks in Azure DevOps
Module 6: Configure Secure Access to Azure Repos from Pipelines Lessons:
Configure pipeline access to packages
Configure credential secrets, and secrets for services
Ensure that the secrets are in the Azure Key Vault
Ensure that secrets aren't in the logs
Module 7: Configure Pipelines to Securely Use Variables and Parameters Lessons:
Ensure that parameters and variables retain their type
Identify and restrict insecure use of parameters and variables
Move parameters into a YAML file that protects their type
Limit variables that can be set at queue time
Validate that mandatory variables are present and set correctly in Azure DevOps
Thank you so much for your time and especially your expertise with us. We really appreciate this discussion session. We gained a lot of technical knowledge today.
SpireTec solutions is the latest technology enabled I.Tmanagement training company specialized in offering 1500+ courses with the state of art training facilities backed by a team of industry experts in various domains with assuring best quality services.
Since SpireTec provides 24X7 training and support for your training needs is very adaptable to your time availabilities and offers customized training programs according to your availability and time zones of your contingent.
Because SpireTec aims for the personal & professional growth of you as individual & corporate as a whole, providing training on the latest and updated versions in the designated domains.
It is preferable but not mandatory to have domain experience in the area of your interest in which you want to opt training, supported by good English communication skills, a good Wi-Fi and computer or laptop system in case you want remote training.
Spire Tec aims and ensure to offer finest and world-class training to the participants by giving them a proper counselling and a guided career path by our industry experts which leads guaranteed success for you in the corporate world.
We offer online training (1-1, Group training), Classroom training, Onsite training with state of art facilities.
We use cookies
Some cookies are essential for this site to function and cannot be turned off. Others are set to help us
understand how our service performs and is used, and to support our marketing efforts.
Learn more in our
Terms &
Privacy Policy.