Granting Pipeline-Scoped Permission So User1 Can Delete a Test Stage in Pipeline1

Design and implement authentication and authorization methods
Answer Correct answer: A — Azure Pipelines has no stage-level permission, so pipeline scope is the narrowest grant letting User1 delete final1 in Pipeline1 under least privilege.

You have an Azure Pipelines pipeline named Pipeline1 and a user named User1. Pipeline1 contains a temporary final stage named final1. You need to ensure that User1 can delete final1 when testing is complete. The solution must follow the principle of least privilege. At which level should you grant permissions to User1?

  1. pipeline Correct Answer
  2. organization
  3. stage
  4. project

Community Votes

A
71%
C
29%

71% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Azure Pipelines permissions can be scoped to an individual pipeline, and because there is no permission level for an individual stage, the pipeline level is the narrowest grant that still lets User1 delete final1 while keeping access inside Pipeline1 only.

Pipeline1 contains a temporary final stage named final1, and User1 must be able to delete final1 once testing finishes. The solution must respect least privilege, so the permission has to be granted at the narrowest level Azure Pipelines actually supports rather than at a broader scope.

Granting permission at the stage level. It reads as the narrowest possible scope, but Azure Pipelines has no stage-level permission, so the grant cannot be created at all, which is why several experienced commenters flagged option C as impossible.

Community Discussion (6 comments)

ahmedMN 👍 2 Selected: A
gpt anwser : Azure Pipelines does not support granting permissions specifically at the stage level. Permissions in Azure DevOps are hierarchical and are typically managed at broader levels, such as the pipeline, project, or organization. A is the correct anwser
Gooldmember 👍 1 Selected: A
Can we interpret the question for YAML pipelines or Release Pipeline? I would go with A and assume it i san YAML pipeline
MrAZ105 👍 1 Selected: C
Principle of Least Privilege: To follow the principle of least privilege, you should grant User1 permissions specifically at the level they need access to, which is the stage level for deleting final1 in Pipeline1. Other Options: A. Pipeline: Granting permissions at the pipeline level would provide broader access than necessary, allowing User1 to make changes to other parts of Pipeline1, not just final1. B. Organization: This would provide access across all pipelines and resources in the organization, which is far beyond what’s required. D. Project: This would give User1 permissions across the entire project, which again exceeds the least privilege needed.
p2006 👍 1 Selected: C
provided answer looks correct for me. https://learn.microsoft.com/en-us/azure/devops/pipelines/policies/permissions?view=azure-devops#set-release-stage-permissions
Emil_Topics 👍 1 Selected: A
Azure DevOps does not have direct permissions for individual stages.
Mattt 👍 1 Selected: A
Azure DevOps does not have direct permissions for individual stages

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is that User1 can delete the stage final1 in Pipeline1, under least privilege. Azure Pipelines exposes permissions at the collection, project, and pipeline levels, and there is no stage-level grant, so the pipeline level is the narrowest scope that actually exists and it confines User1's rights to Pipeline1 alone. That satisfies least privilege because User1 cannot touch any other pipeline in the project or organization. The vote was 71 for A and 29 for C. The strongest supporting evidence came from people who had actually tried it: Mattt and Emil_Topics each stated plainly that Azure DevOps does not have direct permissions for individual stages, and ahmedMN explained that permissions are managed at the broader levels such as pipeline, project, or organization, naming A as the correct answer.

Why the Other Options Are Wrong

Granting permission at the stage level (C) is the most intuitive reading of least privilege and it is what 29 voters chose, with MrAZ105 arguing that stage is the level where the need actually lies and p2006 citing the set-release-stage-permissions section of the permissions documentation. The decisive counterpoint is that the permissions documentation section p2006 points at concerns setting release stage permissions in a deployment, which is a different mechanism from granting a user the right to edit or delete a stage in a YAML pipeline. Since the stage level is not an available grant for this scenario, the option cannot be correct. Granting permission at the project level (D) is broader than necessary because it would let User1 modify or delete stages in every pipeline in the project, not just final1 in Pipeline1. Granting permission at the organization level (B) is broader still, exposing every project and pipeline in the organization to User1.

Community Comment Notes

The community favored A at 71 votes, and the two most useful comments established the fact that decides the question rather than arguing about least privilege in the abstract. Mattt and Emil_Topics both stated that Azure DevOps has no direct permissions for individual stages, which is an existence proof that option C cannot be implemented. Gooldmember added a useful caveat, asking whether the question targets a YAML pipeline or a release pipeline, and concluded A under the YAML assumption. MrAZ105's argument for C is the strongest case for the minority position, resting on the principle of granting access at exactly the level where it is needed, and p2006 backed it with a documentation link; the reconciliation is that the principle is right but the stage-level grant it assumes does not exist in this scenario.

Official Reference

Related Analysis

Practice All AZ-400 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-400 Practice Test →

← Back to AZ-400 Study Guide