Using a Service Principal for a Self-Hosted Agent Deploying Bicep Templates to Azure
You have an Azure subscription. You use Bicep templates to deploy websites and Azure SQL infrastructure. You need to automate the deployments by using Azure Pipelines and a self-hosted agent that runs on two virtual machines. The solution must minimize administrative effort. What should you do first?
Community Votes
50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A service principal is the identity type used for a DevOps service connection, which is what a pipeline uses to authenticate to Azure, and one principal can be shared by both agents without embedding a different credential on each virtual machine, which is the lowest administrative overhead.
Bicep templates deploy websites and Azure SQL infrastructure, and the deployments are automated through Azure Pipelines running on a self-hosted agent on two virtual machines, with minimal administrative effort. The pipeline first needs an identity that the agent can use to authenticate to Azure, and the choice of identity type has to account for the fact that the agent is already running inside Azure.
Creating a managed identity and assigning it per virtual machine. A managed identity requires provisioning the identity on each agent VM and then granting it the Azure RBAC permissions, so two agents mean two identity setups to create and maintain, which is more administrative work than one service principal.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The pipeline runs on a self-hosted agent and must authenticate to Azure in order to deploy Bicep templates, and the mechanism Azure Pipelines provides for that is an Azure service connection backed by a service principal. A service principal is created once in Azure AD, granted the required deployment permissions, and registered as the service connection the pipeline uses, so both agents authenticate with the same identity. Because the question asks what to do first and requires minimal administrative effort, creating that principal once and referencing it from the pipeline is the lowest-effort starting point. The vote was exactly split at 50 for A and 50 for C, so this question has no community majority and the reasoning is decisive.Why the Other Options Are Wrong
Creating a user-assigned managed identity (C) ties the answer to the split, and AlexDa argued for it on the grounds that the agents run on Azure virtual machines, so a managed identity avoids credentials entirely. That reasoning identifies a genuine advantage of managed identities, but it does not survive the minimal-administrative-effort constraint here, because a user-assigned identity still has to be created, assigned to each of the two virtual machines, and granted the deployment role, producing two per-machine configurations. Enabling a system-assigned managed identity on each virtual machine (D) has the same multiplication problem in a worse form, because the identity is created implicitly per VM with its own lifecycle and cannot be shared, so each agent is a separate identity to manage. Creating an Azure Automation account (B) is unrelated to pipeline authentication, since Automation accounts serve runbook and schedule execution rather than acting as a pipeline deployment identity.Community Comment Notes
This question produced an exact tie, 50 for A and 50 for C, so the community provides no majority to defer to. 8fc2e85 supported the service principal on the grounds that the Azure service connection is what each agent uses to deploy to Azure, which is the correct account of the mechanism. AlexDa argued for the user-assigned managed identity with an explicit conditional, that a service principal would be required when deploying from outside Azure such as GitHub Actions, a different cloud, or an on-premises server, and that because the agents are on Azure virtual machines the managed identity is preferable. Both positions identify real properties of their option. The tie is resolved by the question's own minimize-administrative-effort wording, since one principal serves both agents while a managed identity must be provisioned and wired on each virtual machine separately.Official Reference
Related Analysis
Practice All AZ-400 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-400 Practice Test →