Showing category results for Security

Apr 11, 2023
Post comments count5
Post likes count5

Azure DevOps 2023 Q2 Roadmap update 

Gloridel Morales
Gloridel Morales

Yesterday we published an updated list of features we plan to deliver in Q2. Each title includes a link where you can find details about each feature. We expect that this will help bring visibility into the key investments for the upcoming quarter. GitHub Advanced Security We are very excited to announce that GitHub Advanced Security for Azure De...

Azure & CloudDevOpsSecurity
Mar 30, 2023
Post comments count20
Post likes count19

Introducing Service Principal and Managed Identity support on Azure DevOps

Angel Wong
Angel Wong

We are proud to announce that Service Principals and Managed Identities can now be used to authenticate with Azure DevOps. For those who have not heard of them before, these Azure Active Directory identities enable teams to gain access to your Azure DevOps organizations acting as their own application, not as a human user or service account. Why...

DevOpsSecurity
Nov 15, 2022
Post comments count2
Post likes count3

Azure DevOps client libraries migrated to MSAL

Lubomir Sokolovsky
Lubomir Sokolovsky

The Microsoft.VisualStudio.Services.InteractiveClient library is a public NuGet package that takes care of authenticating to Azure DevOps Services. It abstracts away the acquisition, management and refreshing of authentication tokens, so developers can focus on their goals and stay productive. Historically, the interactive client library has been ...

DevOpsSecurity
Nov 9, 2022
Post comments count3
Post likes count5

All Azure DevOps REST APIs now support PAT scopes

Barry Wolfson
Barry Wolfson

Recently, the Azure DevOps team completed an initiative to associate all Azure DevOps REST APIs with a granular personal access token (PAT) scope. As part of our ongoing investments in security, we undertook this effort to reduce the risks associated with a leaked PAT credential. Previously, a number of Azure DevOps REST APIs were not associated wi...

DevOpsAzure & CloudSecurity
Oct 12, 2022
Post comments count24
Post likes count18

Integrate security into your developer workflow with GitHub Advanced Security for Azure DevOps

Aaron Hallberg
Aaron Hallberg

Exciting things are in store for Azure DevOps in the coming year! We’re planning deep investments in security as well as broad investment across the product. Read on for more information, and then be sure to check out our updated roadmap at https://aka.ms/AzureDevOpsRoadmap. Deep investments in security First, we are super excited about bringing ...

DevOpsAzure & CloudSecurity
May 19, 2022
Post comments count37
Post likes count1

Updates to Azure Pipelines Runtime Variables Settings [Updated]

Gloridel Morales
Gloridel Morales

We have gotten a lot of feedback on this change and after internal deliberation, we are now rolling back this change ASAP. Final Update as of 5/19/22 @ 10:08 AM PST: Again, I am deeply sorry for the inconvenience and disruption this has caused. We remain deeply committed to making sure our customers have a first-class experience using Azure ...

Security
May 3, 2022
Post comments count0
Post likes count0

Reconfigure Azure DevOps Server to use Kerberos instead of NTLM

Angel Wong
Angel Wong

Multiple on-prem customers have reported that after upgrading Git LFS to version 3.0 (or higher), they are no longer able to authenticate against Azure DevOps Server. This is because Git LFS has dropped support for NTLM authentication in version 3.0 (Changelog from 24th September 2021). While it is possible to roll back Git LFS to the last 2.x ver...

Azure DevOps ServerSecurity
Feb 25, 2022
Post comments count2
Post likes count0

Top stories from the #AzureDevOps #community for 2022.25.02 are here!

April Yoho
April Yoho

Welcome back! I am April Edwards and every week I try to bring you the latest updates from around the DevOps on Azure community. If you have a post you’d like to have me include, I am always listening. You can reach out on Twitter or LinkedIn and I will be sure to share your latest post with the community. Also, be sure to tag your posts with #Azur...

DevOpsAzure & CloudCommunity
Dec 14, 2021
Post comments count9
Post likes count1

Updated: Azure DevOps (and Azure DevOps Server) and the log4j vulnerability

Gloridel Morales
Gloridel Morales

For Azure DevOps, our analysis pointed towards the Search service not being vulnerable. Even so, we are following the guidance and upgrading to the latest Log4j version and reviewing our network security group rules for the Search service as part of a defense in depth strategy. We will continue posting updates to this blog post as we learn mor

Azure DevOps ServerSecurity