cloudyspells/PSRule.Rules.AzureDevOps

Entra ID SP/MID Authentication

Closed this issue · 0 comments

Story

As a security specialist I want to module to be able to run in a read-only role so I can be confident the module does not make modifications to Azure DevOps.

Acceptance Criteria:

  • Service Principal Authentication with secret
  • Managed Identity Authentication
  • Must store and update token for re-use in the session, so not re-authenticate for each request when doing a full export
  • Document how to set up minimal permissions role + assignment for the module