Using a Service Principal for a Self-Hosted Agent Deploying Bicep Templates to Azure

Design and implement authentication and authorization methods
Answer Correct answer: A — A service principal backs the Azure service connection the pipeline uses, so one identity serves both agents; a managed identity must be wired per VM.

You have an Azure subscription. You use Bicep templates to deploy websites and Azure SQL infrastructure. You need to automate the deployments by using Azure Pipelines and a self-hosted agent that runs on two virtual machines. The solution must minimize administrative effort. What should you do first?

  1. Create a service principal. Correct Answer
  2. Create an Azure Automation account.
  3. Create a user-assigned managed identity.
  4. On each virtual machine, enable a system-assigned managed identity.

Community Votes

A
50%
C
50%

50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A service principal is the identity type used for a DevOps service connection, which is what a pipeline uses to authenticate to Azure, and one principal can be shared by both agents without embedding a different credential on each virtual machine, which is the lowest administrative overhead.

Bicep templates deploy websites and Azure SQL infrastructure, and the deployments are automated through Azure Pipelines running on a self-hosted agent on two virtual machines, with minimal administrative effort. The pipeline first needs an identity that the agent can use to authenticate to Azure, and the choice of identity type has to account for the fact that the agent is already running inside Azure.

Creating a managed identity and assigning it per virtual machine. A managed identity requires provisioning the identity on each agent VM and then granting it the Azure RBAC permissions, so two agents mean two identity setups to create and maintain, which is more administrative work than one service principal.

Community Discussion (3 comments)

AlexDa 👍 1 Selected: C
It is C: User-assigned managed identity If you were deploying from outside Azure (e.g., GitHub Actions, a different cloud, or an on-premises server), then a Service Principal would be required. However, since your self-hosted agent is running on Azure VMs, UAMI is the better choice.
Todo69 👍 1
https://learn.microsoft.com/en-us/azure/devops/pipelines/agents/windows-agent?view=azure-devops Agent setup authentication type When you register an agent, choose from the following authentication types, and setup will prompt you for the specific additional information required for each authentication type. For more information, see Self-hosted agent authentication options. Personal access token Device code flow Service principal
8fc2e85 👍 1 Selected: A
I think answer is correct because service principal for the Azure service connection in devops that each agent will use to deploy to Azure.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The pipeline runs on a self-hosted agent and must authenticate to Azure in order to deploy Bicep templates, and the mechanism Azure Pipelines provides for that is an Azure service connection backed by a service principal. A service principal is created once in Azure AD, granted the required deployment permissions, and registered as the service connection the pipeline uses, so both agents authenticate with the same identity. Because the question asks what to do first and requires minimal administrative effort, creating that principal once and referencing it from the pipeline is the lowest-effort starting point. The vote was exactly split at 50 for A and 50 for C, so this question has no community majority and the reasoning is decisive.

Why the Other Options Are Wrong

Creating a user-assigned managed identity (C) ties the answer to the split, and AlexDa argued for it on the grounds that the agents run on Azure virtual machines, so a managed identity avoids credentials entirely. That reasoning identifies a genuine advantage of managed identities, but it does not survive the minimal-administrative-effort constraint here, because a user-assigned identity still has to be created, assigned to each of the two virtual machines, and granted the deployment role, producing two per-machine configurations. Enabling a system-assigned managed identity on each virtual machine (D) has the same multiplication problem in a worse form, because the identity is created implicitly per VM with its own lifecycle and cannot be shared, so each agent is a separate identity to manage. Creating an Azure Automation account (B) is unrelated to pipeline authentication, since Automation accounts serve runbook and schedule execution rather than acting as a pipeline deployment identity.

Community Comment Notes

This question produced an exact tie, 50 for A and 50 for C, so the community provides no majority to defer to. 8fc2e85 supported the service principal on the grounds that the Azure service connection is what each agent uses to deploy to Azure, which is the correct account of the mechanism. AlexDa argued for the user-assigned managed identity with an explicit conditional, that a service principal would be required when deploying from outside Azure such as GitHub Actions, a different cloud, or an on-premises server, and that because the agents are on Azure virtual machines the managed identity is preferable. Both positions identify real properties of their option. The tie is resolved by the question's own minimize-administrative-effort wording, since one principal serves both agents while a managed identity must be provisioned and wired on each virtual machine separately.

Official Reference

Related Analysis

Practice All AZ-400 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-400 Practice Test →

← Back to AZ-400 Study Guide