Granting User1 Provisioning Rights on Azure Deployment Environments with the Deployment Environments User Role

Design and implement authentication and authorization methods
Answer Correct answer: B — The Deployment Environments User role lets User1 create environments and deploy to their own, the narrowest grant; Contributors does not cover environments.

You have an Azure subscription that contains an Azure Pipelines pipeline named Pipeline1 and a user named User1. Pipeline1 is used to build and test an app named App1. User1 is assigned the Contributors role for Pipeline1. You plan to test App1 by using an Azure Deployment Environments environment. You need to ensure that User1 can provision the environment. The solution must follow the principle of least privilege. Which role should you assign to User1?

  1. DevCenter Project Admin
  2. Deployment Environments User Correct Answer
  3. Contributors
  4. Build Administrators

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The Deployment Environments User role is the least-privilege role for environment work: it allows viewing environment types, creating environments, and deploying to environments the user owns, without granting the broader build, contribute, or admin rights that the other options carry.

User1 has the Contributors role on Pipeline1 and must be able to provision an environment in Azure Deployment Environments to test App1, under least privilege. The role needed is therefore one scoped to deployment environments rather than a broader build or project administration grant.

Reaching for the DevCenter Project Admin role because it also touches environments. It does, but it grants Dev Center-wide administrative control that is far broader than creating and deploying to an environment, so it violates the least privilege requirement the question states.

Community Discussion (3 comments)

BakaPon 👍 5 Selected: B
B. Deployment Environments User When assigned at the project level, a developer who has the Deployment Environments User role can perform the following actions on all enabled project environment types: - View the project environment types. - Create an environment. - Read, write, delete, or perform actions (like deploy or reset) on their own environment. https://learn.microsoft.com/en-us/azure/deployment-environments/how-to-configure-deployment-environments-user
Approach_Belgium_SA 👍 1 Selected: B
Answer is correct
Alandt 👍 2
To ensure that User1 can provision the environment while following the principle of least privilege, you should assign User1 the: B. Deployment Environments User The Deployment Environments User role in Azure Pipelines allows a user to manage environments and their settings, which includes provisioning new environments. This role provides the necessary permissions for User1 to perform the task without granting excessive privileges.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The task is narrow and specific: User1 must be able to provision environments in Azure Deployment Environments, and the solution must respect least privilege. The Deployment Environments User role exists precisely for this scope. When assigned at the project level, it permits viewing the project environment types, creating an environment, and performing actions such as deploy or reset on the user's own environment, and nothing beyond that. That is the narrowest role that still satisfies the requirement, which is exactly what least privilege asks for. The vote was unanimous at 100 for B. BakaPon, with five likes, quoted the role's documented permission list verbatim, which both establishes the answer and demonstrates that it is genuinely scoped to environment operations.

Why the Other Options Are Wrong

The DevCenter Project Admin role (A) is a Dev Center-specific administrative role that grants broad control over the Dev Center configuration and its environments, so it carries far more rights than creating and deploying to an environment requires. The Contributors role (C) is what User1 already holds on Pipeline1, and the fact that the question states this is the clue that it is insufficient: Contributors does not by itself grant the deployment environments permissions needed to provision environments, which is why an additional role is being asked for. The Build Administrators role (D) is scoped to managing build resources such as agents and build definitions, which has no bearing on environment provisioning.

Community Comment Notes

The community was unanimous at 100 for B. BakaPon's comment was decisive because it reproduced the documented permission list for the Deployment Environments User role at project scope, showing that environment creation and self-service deploy or reset are inside the role while nothing broader is. Alandt gave the complementary half of the reasoning, explaining that the role allows a user to manage environments and their settings including provisioning new environments, and noted that this provides what User1 needs without extra permission. The question is well constructed in that option C is explicitly ruled out by the stem stating User1 already holds it.

Related Analysis

Practice All AZ-400 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-400 Practice Test →

← Back to AZ-400 Study Guide