You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无需用户DevOps PAT,基于AAD凭证或VM托管身份实现Azure DevOps认证并触发发布管道的PowerShell方案咨询

Alternatives to User PAT for Azure DevOps Release Pipeline Authentication via PowerShell

Absolutely! You can ditch the user PAT and use either AAD user credentials or managed identities (system-assigned or user-assigned) to authenticate to Azure DevOps and interact with release pipelines from your VM1. Let’s break down both options with practical PowerShell implementations:

Option 1: Authenticate with AAD User Credentials

You can use the Azure PowerShell module to fetch an AAD access token for Azure DevOps, then use that token to call the Release Management API. This avoids hardcoding or storing a PAT in your scripts.

PowerShell Script:

# Install the Azure Accounts module if not present (run once)
# Install-Module Az.Accounts -Force -AllowClobber

# Authenticate with your AAD credentials (interactive prompt, or use -Credential for non-interactive)
Connect-AzAccount -TenantId "your-aad-tenant-id"

# Fetch an access token for Azure DevOps (fixed resource ID for Azure DevOps)
$adoToken = (Get-AzAccessToken -ResourceUrl "499b84ac-1321-427f-aa17-267ca6975798").Token

# Define your target Azure DevOps release API endpoint
$apiUrl = "https://vsrm.dev.azure.com/MyOrg/MyProject/_apis/release/releases?definitionId=7&`$top=100&api-version=6.0"

# Invoke the API using the AAD token as Bearer authentication
Invoke-RestMethod -Method Get -Uri $apiUrl -ContentType "application/json" -Headers @{
    Authorization = "Bearer $adoToken"
}

Key Notes:

  • The resource ID 499b84ac-1321-427f-aa17-267ca6975798 is a fixed identifier for Azure DevOps in AAD.
  • For non-interactive scenarios, use $cred = Get-Credential and pass -Credential $cred to Connect-AzAccount.
  • Ensure the AAD user has the necessary Azure DevOps permissions (e.g., "Create release" or "Edit release pipeline" for your target definition).

Option 2: Authenticate with Managed Identity (System or User-Assigned)

Managed identities are the most secure and low-maintenance option for VM automation—they eliminate credential storage entirely, as Azure handles identity authentication behind the scenes.

Prerequisites:

  1. Enable managed identity on VM1:
    • System-assigned: Toggle on "System assigned" under your VM’s Identity settings in the Azure Portal.
    • User-assigned: Create a user-assigned managed identity in Azure, then assign it to your VM via the Identity > User assigned tab.
  2. Grant permissions to the identity in Azure DevOps:
    • Managed identities are AAD service principals. Go to your Azure DevOps Organization > Settings > Users > Add user, search for the identity’s name, and add it to a project group with required release permissions (e.g., "Release Administrators" or custom pipeline-specific permissions).

PowerShell Script:

# Authenticate using the VM's managed identity (works for both system and user-assigned)
# For user-assigned identities, add: -IdentityClientId "your-user-assigned-identity-client-id"
Connect-AzAccount -Identity

# Fetch the access token for Azure DevOps
$adoToken = (Get-AzAccessToken -ResourceUrl "499b84ac-1321-427f-aa17-267ca6975798").Token

# Define your Azure DevOps release API endpoint
$apiUrl = "https://vsrm.dev.azure.com/MyOrg/MyProject/_apis/release/releases?definitionId=7&`$top=100&api-version=6.0"

# Call the API with the managed identity's token
Invoke-RestMethod -Method Get -Uri $apiUrl -ContentType "application/json" -Headers @{
    Authorization = "Bearer $adoToken"
}

Key Notes:

  • No credentials are needed in the script—authentication is handled automatically by Azure for the VM’s identity.
  • Wait 5-10 minutes after adding the service principal to Azure DevOps for permissions to propagate.
  • This is the recommended approach for long-running VM automation, as it removes the need to rotate or secure secrets.

Both options fully replace the user PAT and align with Azure security best practices. For VM-based workflows, managed identities are the clear winner due to their zero-credential overhead.

内容的提问来源于stack exchange,提问作者NewUser

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 22:02:29