• Landing Page
  • Shop
  • Contact
  • Privacy Policy
  • Login
  • Register
Upgrade
TrivDaily
">
  • WorldNew
    Pound

    Pound hits 37-year low against dollar

    Palm Trees - WIND

    Hurricane Tracker : Tropical Storm Hurricane Nine has the potential to reach Florida

    Prince of Wales - TrivDaily

    Princess Diana’s title has been passed on to the Duchess of Cambridge

    TrivDaily - King Charles Speech

    3 main points to be gleaned from King Charles first public speech

    Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

    Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

    The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

    The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

    Hibernian  beat Arsenal 2-1 in first preseason game on Easter Road

    Hibernian beat Arsenal 2-1 in first preseason game on Easter Road

    After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

    After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

    Lionel Messi, Argentina win Copa America over Brazil

    Lionel Messi, Argentina win Copa America over Brazil

    Trending Tags

    • Lifestyle
      UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

      UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

      bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

      bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

      Crystal Palace into Champions League places as Guehi scores late winner at Fulham

      UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

      UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

      Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

      Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

      ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

      ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

      Trending Tags

      • Pandemic
    • Business
      Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

      Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

      Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

      Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

      Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

      Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

      Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

      Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

      Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

      Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

      Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

      Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

      Trending Tags

      • Vaccine
      • Pandemic
    • Entertainment
      Court dismisses £1.5m problem gambling claim against Betfair for second time

      Court dismisses £1.5m problem gambling claim against Betfair for second time

      Sophia Thakur’s Lexicon Is Love

      Sophia Thakur’s Lexicon Is Love

      President Trump awards medals to Sly Stallone, George Strait and more

      President Trump awards medals to Sly Stallone, George Strait and more

      Supplier Supplement: fraudsters, storytelling and technology

      Supplier Supplement: fraudsters, storytelling and technology

      Fred again.. And Blanco Combine On ‘Solo’

      Fred again.. And Blanco Combine On ‘Solo’

      Moonstone Rings: A Timeless Addition to Your Jewelry Collection

      Moonstone Rings: A Timeless Addition to Your Jewelry Collection

      The six Latin American markets the betting industry should keep an eye on

      The six Latin American markets the betting industry should keep an eye on

      Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

      Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

      Peru escalates dispute of Dina’s tax encroachment 

      Peru escalates dispute of Dina’s tax encroachment 

      Trending Tags

      • Sports
        Dusty May: No. 2 Michigan ‘Deserves’ to Be No. 1 After Dominating Villanova

        Dusty May: No. 2 Michigan ‘Deserves’ to Be No. 1 After Dominating Villanova

        AJ Dybantsa’s Career Night, Robert Wright III’s GW Lifts No. 10 BYU Past Clemson

        AJ Dybantsa’s Career Night, Robert Wright III’s GW Lifts No. 10 BYU Past Clemson

        Gen Z Trades Doomscrolling for Real-World Sweat: Key Takeaways from Strava’s 12th Year in Sport Report

        Gen Z Trades Doomscrolling for Real-World Sweat: Key Takeaways from Strava’s 12th Year in Sport Report

        Eagles at Chargers Live Updates | Monday Night Football

        Eagles at Chargers Live Updates | Monday Night Football

        Stake Canada App — Download, Legality, Features & How-To (2025)

        Stake Canada App — Download, Legality, Features & How-To (2025)

        Buccaneers’ NFC South Chances Take Massive Hit After Loss to Saints

        Buccaneers’ NFC South Chances Take Massive Hit After Loss to Saints

        Dallas Cowboys may have found a late-round gem in WR Ryan Flournoy

        Dallas Cowboys may have found a late-round gem in WR Ryan Flournoy

        Cowboys 2025 rookie report: Rookie class was flat in battle against the Lions

        Cowboys 2025 rookie report: Rookie class was flat in battle against the Lions

        Rockets’ Kevin Durant Latest to Score 31K Career Points During Win vs. Suns

        Rockets’ Kevin Durant Latest to Score 31K Career Points During Win vs. Suns

        Trending Tags

        • Travel
          Football’s biggest names including Mbappe and Haaland rally behind Mohamed Salah after Liverpool axe

          Football’s biggest names including Mbappe and Haaland rally behind Mohamed Salah after Liverpool axe

          Man Utd face Premier League bogey side and Arsenal travel to former winners as full FA Cup Third Round draw revealed

          Man Utd face Premier League bogey side and Arsenal travel to former winners as full FA Cup Third Round draw revealed

          Finding stillness in Kyoto: My solo journey through Japan’s most peaceful retreats

          Finding stillness in Kyoto: My solo journey through Japan’s most peaceful retreats

          Saudi giants enquire about Liverpool star Salah

          Saudi giants enquire about Liverpool star Salah

          Christmas chaos warning as staff set to strike at major UK airport

          Christmas chaos warning as staff set to strike at major UK airport

          How volcanic eruptions brought the Black Death to Europe

          How volcanic eruptions brought the Black Death to Europe

          Trending Tags

          • Technology
            UK to Europe: The time to counter Russia’s information war machine is now

            UK to Europe: The time to counter Russia’s information war machine is now

            Affection for Excel spans generations, from Boomers to Zoomers

            Affection for Excel spans generations, from Boomers to Zoomers

            Trump’s EPA Plans to Raise Threshold for ‘Safe’ Formaldehyde Exposure

            Trump’s EPA Plans to Raise Threshold for ‘Safe’ Formaldehyde Exposure

            A New Meta Quest Probably Won’t Happen in 2026

            A New Meta Quest Probably Won’t Happen in 2026

            And the winner of the Microsoft Christmas sweater is…

            And the winner of the Microsoft Christmas sweater is…

            Death to one-time text codes: Passkeys are the new hotness in MFA

            Death to one-time text codes: Passkeys are the new hotness in MFA

            Trending Tags

            • Real Estate
              Malaysia Plans To Open Worldwide Tourism On December 1

              Malaysia Plans To Open Worldwide Tourism On December 1

              #1 UK housing: renting has turn out to be less expensive than shopping

              #1 UK housing: renting has turn out to be less expensive than shopping

              UK assets marketplace pastime maintains at record-breaking levels

              UK assets marketplace pastime maintains at record-breaking levels

              GUUD Launches New RYTE Financing Platform To Make Trade Finance Accessible for All Businesses

              GUUD Launches New RYTE Financing Platform To Make Trade Finance Accessible for All Businesses

              Climate Finance Partnership Raises US$250 Million at First Close to Invest in Emerging Market Climate Infrastructure

              Climate Finance Partnership Raises US$250 Million at First Close to Invest in Emerging Market Climate Infrastructure

              Interior Jennifer Lopez’s luxe Miami rental: 5 stress-free details in regards to the mansion

              Interior Jennifer Lopez’s luxe Miami rental: 5 stress-free details in regards to the mansion

              Trending Tags

              No Result
              View All Result
              • WorldNew
                Pound

                Pound hits 37-year low against dollar

                Palm Trees - WIND

                Hurricane Tracker : Tropical Storm Hurricane Nine has the potential to reach Florida

                Prince of Wales - TrivDaily

                Princess Diana’s title has been passed on to the Duchess of Cambridge

                TrivDaily - King Charles Speech

                3 main points to be gleaned from King Charles first public speech

                Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

                Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

                The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

                The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

                Hibernian  beat Arsenal 2-1 in first preseason game on Easter Road

                Hibernian beat Arsenal 2-1 in first preseason game on Easter Road

                After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

                After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

                Lionel Messi, Argentina win Copa America over Brazil

                Lionel Messi, Argentina win Copa America over Brazil

                Trending Tags

                • Lifestyle
                  UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

                  UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

                  bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

                  bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

                  Crystal Palace into Champions League places as Guehi scores late winner at Fulham

                  UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

                  UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

                  Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

                  Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

                  ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

                  ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

                  Trending Tags

                  • Pandemic
                • Business
                  Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

                  Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

                  Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

                  Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

                  Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

                  Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

                  Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

                  Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

                  Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

                  Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

                  Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

                  Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

                  Trending Tags

                  • Vaccine
                  • Pandemic
                • Entertainment
                  Court dismisses £1.5m problem gambling claim against Betfair for second time

                  Court dismisses £1.5m problem gambling claim against Betfair for second time

                  Sophia Thakur’s Lexicon Is Love

                  Sophia Thakur’s Lexicon Is Love

                  President Trump awards medals to Sly Stallone, George Strait and more

                  President Trump awards medals to Sly Stallone, George Strait and more

                  Supplier Supplement: fraudsters, storytelling and technology

                  Supplier Supplement: fraudsters, storytelling and technology

                  Fred again.. And Blanco Combine On ‘Solo’

                  Fred again.. And Blanco Combine On ‘Solo’

                  Moonstone Rings: A Timeless Addition to Your Jewelry Collection

                  Moonstone Rings: A Timeless Addition to Your Jewelry Collection

                  The six Latin American markets the betting industry should keep an eye on

                  The six Latin American markets the betting industry should keep an eye on

                  Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

                  Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

                  Peru escalates dispute of Dina’s tax encroachment 

                  Peru escalates dispute of Dina’s tax encroachment 

                  Trending Tags

                  • Sports
                    Dusty May: No. 2 Michigan ‘Deserves’ to Be No. 1 After Dominating Villanova

                    Dusty May: No. 2 Michigan ‘Deserves’ to Be No. 1 After Dominating Villanova

                    AJ Dybantsa’s Career Night, Robert Wright III’s GW Lifts No. 10 BYU Past Clemson

                    AJ Dybantsa’s Career Night, Robert Wright III’s GW Lifts No. 10 BYU Past Clemson

                    Gen Z Trades Doomscrolling for Real-World Sweat: Key Takeaways from Strava’s 12th Year in Sport Report

                    Gen Z Trades Doomscrolling for Real-World Sweat: Key Takeaways from Strava’s 12th Year in Sport Report

                    Eagles at Chargers Live Updates | Monday Night Football

                    Eagles at Chargers Live Updates | Monday Night Football

                    Stake Canada App — Download, Legality, Features & How-To (2025)

                    Stake Canada App — Download, Legality, Features & How-To (2025)

                    Buccaneers’ NFC South Chances Take Massive Hit After Loss to Saints

                    Buccaneers’ NFC South Chances Take Massive Hit After Loss to Saints

                    Dallas Cowboys may have found a late-round gem in WR Ryan Flournoy

                    Dallas Cowboys may have found a late-round gem in WR Ryan Flournoy

                    Cowboys 2025 rookie report: Rookie class was flat in battle against the Lions

                    Cowboys 2025 rookie report: Rookie class was flat in battle against the Lions

                    Rockets’ Kevin Durant Latest to Score 31K Career Points During Win vs. Suns

                    Rockets’ Kevin Durant Latest to Score 31K Career Points During Win vs. Suns

                    Trending Tags

                    • Travel
                      Football’s biggest names including Mbappe and Haaland rally behind Mohamed Salah after Liverpool axe

                      Football’s biggest names including Mbappe and Haaland rally behind Mohamed Salah after Liverpool axe

                      Man Utd face Premier League bogey side and Arsenal travel to former winners as full FA Cup Third Round draw revealed

                      Man Utd face Premier League bogey side and Arsenal travel to former winners as full FA Cup Third Round draw revealed

                      Finding stillness in Kyoto: My solo journey through Japan’s most peaceful retreats

                      Finding stillness in Kyoto: My solo journey through Japan’s most peaceful retreats

                      Saudi giants enquire about Liverpool star Salah

                      Saudi giants enquire about Liverpool star Salah

                      Christmas chaos warning as staff set to strike at major UK airport

                      Christmas chaos warning as staff set to strike at major UK airport

                      How volcanic eruptions brought the Black Death to Europe

                      How volcanic eruptions brought the Black Death to Europe

                      Trending Tags

                      • Technology
                        UK to Europe: The time to counter Russia’s information war machine is now

                        UK to Europe: The time to counter Russia’s information war machine is now

                        Affection for Excel spans generations, from Boomers to Zoomers

                        Affection for Excel spans generations, from Boomers to Zoomers

                        Trump’s EPA Plans to Raise Threshold for ‘Safe’ Formaldehyde Exposure

                        Trump’s EPA Plans to Raise Threshold for ‘Safe’ Formaldehyde Exposure

                        A New Meta Quest Probably Won’t Happen in 2026

                        A New Meta Quest Probably Won’t Happen in 2026

                        And the winner of the Microsoft Christmas sweater is…

                        And the winner of the Microsoft Christmas sweater is…

                        Death to one-time text codes: Passkeys are the new hotness in MFA

                        Death to one-time text codes: Passkeys are the new hotness in MFA

                        Trending Tags

                        • Real Estate
                          Malaysia Plans To Open Worldwide Tourism On December 1

                          Malaysia Plans To Open Worldwide Tourism On December 1

                          #1 UK housing: renting has turn out to be less expensive than shopping

                          #1 UK housing: renting has turn out to be less expensive than shopping

                          UK assets marketplace pastime maintains at record-breaking levels

                          UK assets marketplace pastime maintains at record-breaking levels

                          GUUD Launches New RYTE Financing Platform To Make Trade Finance Accessible for All Businesses

                          GUUD Launches New RYTE Financing Platform To Make Trade Finance Accessible for All Businesses

                          Climate Finance Partnership Raises US$250 Million at First Close to Invest in Emerging Market Climate Infrastructure

                          Climate Finance Partnership Raises US$250 Million at First Close to Invest in Emerging Market Climate Infrastructure

                          Interior Jennifer Lopez’s luxe Miami rental: 5 stress-free details in regards to the mansion

                          Interior Jennifer Lopez’s luxe Miami rental: 5 stress-free details in regards to the mansion

                          Trending Tags

                          No Result
                          View All Result
                          TrivDaily
                          No Result
                          View All Result
                          Home Technology

                          Microsoft’s security roadmap: Protect secrets in Azure DevOps

                          Ferhan Rana by Ferhan Rana
                          July 17, 2023
                          in Technology
                          Reading Time:4 mins read
                          31.5k 318
                          A A
                          0
                          Microsoft’s security roadmap: Protect secrets in Azure DevOps
                          29.7k
                          SHARES
                          33.8k
                          VIEWS
                          Share on FacebookShare on Twitter
                          ">

                          Microsoft has vowed to bulk up security around its Azure DevOps cloud services developers use to build their applications and manage their software projects.

                          The security enhancements are part of the larger roadmap for Azure DevOps that the cloud giant laid out this week that also includes additions to Azure Boards – for tracking ideas throughout the development lifecycle – and Azure Pipelines to automatically build and test code.

                          The changes also come as Microsoft bolsters its Entra suite of cloud-based identity and access services, not only by ditching the Azure AD name in favor of Entra ID – a move not fully embraced by all users – but also through its first offerings in the fast-growing security services edge (SSE) space.

                          One focus for Redmond is the GitHub code repository, which like other code bases – such as NPM and the Python Package Index (PyPI) – has become a target for criminals in supply chain attacks aimed at getting developers to inadvertently dropping malicious code into their applications.

                          GitHub Advanced Security (GHAS) for Azure DevOps is a suite of tools developers can use to protect their Azure Repos repositories and Pipelines. These include secret scanning to detect such secrets as credentials already in Azure Repos and ways to keep developers from accidentally pushing new secrets and dependency scanning, so they can find known vulnerable open-source packages and fix any problems.

                          Also in GHAS – which is in public preview and integrated into Azure DevOps – is code scanning, which uses GitHub’s CodeQL semantic analysis engine to identity app security flaws in the source code.

                          Authentication on the menu

                          Identity and authentication also will factor heavily in what Microsoft does through at least the rest of the year. The vendor for several years has banged the drum for improved authentication tools – such as ModernAuth and passkeys – as identity becomes a key focus for cyber-attackers.

                          In Azure DevOps, a key risk is credential theft.

                          “Azure DevOps supports many different authentication mechanisms, including basic authentication, personal access tokens (PATs), SSH, and Azure Active Directory access tokens,” the company wrote. “These mechanisms are not created equal from a security perspective, especially when it comes to the potential for credential theft.”

                          • Miscreants exploit five Microsoft bugs as Windows giant addresses 130 flaws
                          • Microsoft keeps quiet amid talk of possible DDoS attack against Azure
                          • Microsoft’s Azure mishap betrays an industry blind to a big problem
                          • This typo sparked a Microsoft Azure outage

                          Criminals can use leaked credentials like PATs to get into organizations using Azure DevOps and access source code, launch supply chain attacks, or compromise the infrastructure.

                          Microsoft will also release Workload Identity federation for Azure Deployments, first in public preview in the third quarter and then generally by the end of the year. Developers are wary of storing secrets like passwords or certificate in Azure DevOps because they become vulnerable to theft when service connections in Azure DevOps are updated.

                          Protection through federation

                          Azure will use the Open ID Connect protocol to support workload identity federation and create service connections in Azure Pipelines that don’t access secrets and which are backed by managed identities with federated credentials in Azure AD.

                          “As part of its execution, a pipeline can exchange its own internal token with an AAD token, thereby gaining access to Azure resources,” Microsoft wrote. “Once implemented, this mechanism will be recommended in the product over other types of Azure service connections that exist today.”

                          Microsoft also will support granular scopes to limit the operations of Azure AD OAuth applications, such as viewing source code or configuring pipelines, when connecting to Azure DevOps.

                          Also by the end of 2023, Microsoft will let applications use managed identities and service principals when integrating with Azure DevOps through REST APIs and client libraries. Most applications now integrate through PATs.

                          “This highly requested feature offers Azure DevOps customers a more secure alternative to PATs,” Redmond wrote. “And Managed Identities offer the ability for applications running on Azure resources to obtain Azure AD tokens without needing to manage any credentials at all.”

                          Microsoft takes to SSE

                          All this comes the same week Microsoft made changes in its Entra suite. The first, as we’ve documented, was the name change from Azure AD to Entra. Another key one was the rollout into public preview of Entra Internet Access and Entra Private Access, Redmond’s first SSE offerings.

                          Secure Access Service Edge (SASE) hit the scene several years ago when enterprises, faced with having to manage security and identity wirelessly, wanted vendors to converge software-defined WAN and network security functions, such as zero trust, firewall-as-a-service (FWaaS), and cloud access security broker (CASB), into a cloud service.

                          SSE emerged during the pandemic, essentially ditching the SD-WAN functions and unifying CASB, zero trust, and secure web gateway (SWG) into a service. Microsoft is coming into this space late, with vendors like Cisco, Zscaler, and Palo Alto Networks, among others, already a year or two ahead.

                          However, Microsoft’s sheer gravitational pull will help it gain market share, as shown by the drop in share prices of Cloudflare, Palo Alto, and Zscaler right after Microsoft announced its SSE move. ®

                          ">

                          Microsoft has vowed to bulk up security around its Azure DevOps cloud services developers use to build their applications and manage their software projects.

                          The security enhancements are part of the larger roadmap for Azure DevOps that the cloud giant laid out this week that also includes additions to Azure Boards – for tracking ideas throughout the development lifecycle – and Azure Pipelines to automatically build and test code.

                          The changes also come as Microsoft bolsters its Entra suite of cloud-based identity and access services, not only by ditching the Azure AD name in favor of Entra ID – a move not fully embraced by all users – but also through its first offerings in the fast-growing security services edge (SSE) space.

                          One focus for Redmond is the GitHub code repository, which like other code bases – such as NPM and the Python Package Index (PyPI) – has become a target for criminals in supply chain attacks aimed at getting developers to inadvertently dropping malicious code into their applications.

                          GitHub Advanced Security (GHAS) for Azure DevOps is a suite of tools developers can use to protect their Azure Repos repositories and Pipelines. These include secret scanning to detect such secrets as credentials already in Azure Repos and ways to keep developers from accidentally pushing new secrets and dependency scanning, so they can find known vulnerable open-source packages and fix any problems.

                          Also in GHAS – which is in public preview and integrated into Azure DevOps – is code scanning, which uses GitHub’s CodeQL semantic analysis engine to identity app security flaws in the source code.

                          Authentication on the menu

                          Identity and authentication also will factor heavily in what Microsoft does through at least the rest of the year. The vendor for several years has banged the drum for improved authentication tools – such as ModernAuth and passkeys – as identity becomes a key focus for cyber-attackers.

                          In Azure DevOps, a key risk is credential theft.

                          “Azure DevOps supports many different authentication mechanisms, including basic authentication, personal access tokens (PATs), SSH, and Azure Active Directory access tokens,” the company wrote. “These mechanisms are not created equal from a security perspective, especially when it comes to the potential for credential theft.”

                          • Miscreants exploit five Microsoft bugs as Windows giant addresses 130 flaws
                          • Microsoft keeps quiet amid talk of possible DDoS attack against Azure
                          • Microsoft’s Azure mishap betrays an industry blind to a big problem
                          • This typo sparked a Microsoft Azure outage

                          Criminals can use leaked credentials like PATs to get into organizations using Azure DevOps and access source code, launch supply chain attacks, or compromise the infrastructure.

                          Microsoft will also release Workload Identity federation for Azure Deployments, first in public preview in the third quarter and then generally by the end of the year. Developers are wary of storing secrets like passwords or certificate in Azure DevOps because they become vulnerable to theft when service connections in Azure DevOps are updated.

                          Protection through federation

                          Azure will use the Open ID Connect protocol to support workload identity federation and create service connections in Azure Pipelines that don’t access secrets and which are backed by managed identities with federated credentials in Azure AD.

                          “As part of its execution, a pipeline can exchange its own internal token with an AAD token, thereby gaining access to Azure resources,” Microsoft wrote. “Once implemented, this mechanism will be recommended in the product over other types of Azure service connections that exist today.”

                          Microsoft also will support granular scopes to limit the operations of Azure AD OAuth applications, such as viewing source code or configuring pipelines, when connecting to Azure DevOps.

                          Also by the end of 2023, Microsoft will let applications use managed identities and service principals when integrating with Azure DevOps through REST APIs and client libraries. Most applications now integrate through PATs.

                          “This highly requested feature offers Azure DevOps customers a more secure alternative to PATs,” Redmond wrote. “And Managed Identities offer the ability for applications running on Azure resources to obtain Azure AD tokens without needing to manage any credentials at all.”

                          Microsoft takes to SSE

                          All this comes the same week Microsoft made changes in its Entra suite. The first, as we’ve documented, was the name change from Azure AD to Entra. Another key one was the rollout into public preview of Entra Internet Access and Entra Private Access, Redmond’s first SSE offerings.

                          Secure Access Service Edge (SASE) hit the scene several years ago when enterprises, faced with having to manage security and identity wirelessly, wanted vendors to converge software-defined WAN and network security functions, such as zero trust, firewall-as-a-service (FWaaS), and cloud access security broker (CASB), into a cloud service.

                          SSE emerged during the pandemic, essentially ditching the SD-WAN functions and unifying CASB, zero trust, and secure web gateway (SWG) into a service. Microsoft is coming into this space late, with vendors like Cisco, Zscaler, and Palo Alto Networks, among others, already a year or two ahead.

                          However, Microsoft’s sheer gravitational pull will help it gain market share, as shown by the drop in share prices of Cloudflare, Palo Alto, and Zscaler right after Microsoft announced its SSE move. ®

                          ">

                          Microsoft has vowed to bulk up security around its Azure DevOps cloud services developers use to build their applications and manage their software projects.

                          The security enhancements are part of the larger roadmap for Azure DevOps that the cloud giant laid out this week that also includes additions to Azure Boards – for tracking ideas throughout the development lifecycle – and Azure Pipelines to automatically build and test code.

                          The changes also come as Microsoft bolsters its Entra suite of cloud-based identity and access services, not only by ditching the Azure AD name in favor of Entra ID – a move not fully embraced by all users – but also through its first offerings in the fast-growing security services edge (SSE) space.

                          One focus for Redmond is the GitHub code repository, which like other code bases – such as NPM and the Python Package Index (PyPI) – has become a target for criminals in supply chain attacks aimed at getting developers to inadvertently dropping malicious code into their applications.

                          GitHub Advanced Security (GHAS) for Azure DevOps is a suite of tools developers can use to protect their Azure Repos repositories and Pipelines. These include secret scanning to detect such secrets as credentials already in Azure Repos and ways to keep developers from accidentally pushing new secrets and dependency scanning, so they can find known vulnerable open-source packages and fix any problems.

                          Also in GHAS – which is in public preview and integrated into Azure DevOps – is code scanning, which uses GitHub’s CodeQL semantic analysis engine to identity app security flaws in the source code.

                          Authentication on the menu

                          Identity and authentication also will factor heavily in what Microsoft does through at least the rest of the year. The vendor for several years has banged the drum for improved authentication tools – such as ModernAuth and passkeys – as identity becomes a key focus for cyber-attackers.

                          In Azure DevOps, a key risk is credential theft.

                          “Azure DevOps supports many different authentication mechanisms, including basic authentication, personal access tokens (PATs), SSH, and Azure Active Directory access tokens,” the company wrote. “These mechanisms are not created equal from a security perspective, especially when it comes to the potential for credential theft.”

                          • Miscreants exploit five Microsoft bugs as Windows giant addresses 130 flaws
                          • Microsoft keeps quiet amid talk of possible DDoS attack against Azure
                          • Microsoft’s Azure mishap betrays an industry blind to a big problem
                          • This typo sparked a Microsoft Azure outage

                          Criminals can use leaked credentials like PATs to get into organizations using Azure DevOps and access source code, launch supply chain attacks, or compromise the infrastructure.

                          Microsoft will also release Workload Identity federation for Azure Deployments, first in public preview in the third quarter and then generally by the end of the year. Developers are wary of storing secrets like passwords or certificate in Azure DevOps because they become vulnerable to theft when service connections in Azure DevOps are updated.

                          Protection through federation

                          Azure will use the Open ID Connect protocol to support workload identity federation and create service connections in Azure Pipelines that don’t access secrets and which are backed by managed identities with federated credentials in Azure AD.

                          “As part of its execution, a pipeline can exchange its own internal token with an AAD token, thereby gaining access to Azure resources,” Microsoft wrote. “Once implemented, this mechanism will be recommended in the product over other types of Azure service connections that exist today.”

                          Microsoft also will support granular scopes to limit the operations of Azure AD OAuth applications, such as viewing source code or configuring pipelines, when connecting to Azure DevOps.

                          Also by the end of 2023, Microsoft will let applications use managed identities and service principals when integrating with Azure DevOps through REST APIs and client libraries. Most applications now integrate through PATs.

                          “This highly requested feature offers Azure DevOps customers a more secure alternative to PATs,” Redmond wrote. “And Managed Identities offer the ability for applications running on Azure resources to obtain Azure AD tokens without needing to manage any credentials at all.”

                          Microsoft takes to SSE

                          All this comes the same week Microsoft made changes in its Entra suite. The first, as we’ve documented, was the name change from Azure AD to Entra. Another key one was the rollout into public preview of Entra Internet Access and Entra Private Access, Redmond’s first SSE offerings.

                          Secure Access Service Edge (SASE) hit the scene several years ago when enterprises, faced with having to manage security and identity wirelessly, wanted vendors to converge software-defined WAN and network security functions, such as zero trust, firewall-as-a-service (FWaaS), and cloud access security broker (CASB), into a cloud service.

                          SSE emerged during the pandemic, essentially ditching the SD-WAN functions and unifying CASB, zero trust, and secure web gateway (SWG) into a service. Microsoft is coming into this space late, with vendors like Cisco, Zscaler, and Palo Alto Networks, among others, already a year or two ahead.

                          However, Microsoft’s sheer gravitational pull will help it gain market share, as shown by the drop in share prices of Cloudflare, Palo Alto, and Zscaler right after Microsoft announced its SSE move. ®

                          ">

                          Microsoft has vowed to bulk up security around its Azure DevOps cloud services developers use to build their applications and manage their software projects.

                          The security enhancements are part of the larger roadmap for Azure DevOps that the cloud giant laid out this week that also includes additions to Azure Boards – for tracking ideas throughout the development lifecycle – and Azure Pipelines to automatically build and test code.

                          The changes also come as Microsoft bolsters its Entra suite of cloud-based identity and access services, not only by ditching the Azure AD name in favor of Entra ID – a move not fully embraced by all users – but also through its first offerings in the fast-growing security services edge (SSE) space.

                          One focus for Redmond is the GitHub code repository, which like other code bases – such as NPM and the Python Package Index (PyPI) – has become a target for criminals in supply chain attacks aimed at getting developers to inadvertently dropping malicious code into their applications.

                          GitHub Advanced Security (GHAS) for Azure DevOps is a suite of tools developers can use to protect their Azure Repos repositories and Pipelines. These include secret scanning to detect such secrets as credentials already in Azure Repos and ways to keep developers from accidentally pushing new secrets and dependency scanning, so they can find known vulnerable open-source packages and fix any problems.

                          Also in GHAS – which is in public preview and integrated into Azure DevOps – is code scanning, which uses GitHub’s CodeQL semantic analysis engine to identity app security flaws in the source code.

                          Authentication on the menu

                          Identity and authentication also will factor heavily in what Microsoft does through at least the rest of the year. The vendor for several years has banged the drum for improved authentication tools – such as ModernAuth and passkeys – as identity becomes a key focus for cyber-attackers.

                          In Azure DevOps, a key risk is credential theft.

                          “Azure DevOps supports many different authentication mechanisms, including basic authentication, personal access tokens (PATs), SSH, and Azure Active Directory access tokens,” the company wrote. “These mechanisms are not created equal from a security perspective, especially when it comes to the potential for credential theft.”

                          • Miscreants exploit five Microsoft bugs as Windows giant addresses 130 flaws
                          • Microsoft keeps quiet amid talk of possible DDoS attack against Azure
                          • Microsoft’s Azure mishap betrays an industry blind to a big problem
                          • This typo sparked a Microsoft Azure outage

                          Criminals can use leaked credentials like PATs to get into organizations using Azure DevOps and access source code, launch supply chain attacks, or compromise the infrastructure.

                          Microsoft will also release Workload Identity federation for Azure Deployments, first in public preview in the third quarter and then generally by the end of the year. Developers are wary of storing secrets like passwords or certificate in Azure DevOps because they become vulnerable to theft when service connections in Azure DevOps are updated.

                          Protection through federation

                          Azure will use the Open ID Connect protocol to support workload identity federation and create service connections in Azure Pipelines that don’t access secrets and which are backed by managed identities with federated credentials in Azure AD.

                          “As part of its execution, a pipeline can exchange its own internal token with an AAD token, thereby gaining access to Azure resources,” Microsoft wrote. “Once implemented, this mechanism will be recommended in the product over other types of Azure service connections that exist today.”

                          Microsoft also will support granular scopes to limit the operations of Azure AD OAuth applications, such as viewing source code or configuring pipelines, when connecting to Azure DevOps.

                          Also by the end of 2023, Microsoft will let applications use managed identities and service principals when integrating with Azure DevOps through REST APIs and client libraries. Most applications now integrate through PATs.

                          “This highly requested feature offers Azure DevOps customers a more secure alternative to PATs,” Redmond wrote. “And Managed Identities offer the ability for applications running on Azure resources to obtain Azure AD tokens without needing to manage any credentials at all.”

                          Microsoft takes to SSE

                          All this comes the same week Microsoft made changes in its Entra suite. The first, as we’ve documented, was the name change from Azure AD to Entra. Another key one was the rollout into public preview of Entra Internet Access and Entra Private Access, Redmond’s first SSE offerings.

                          Secure Access Service Edge (SASE) hit the scene several years ago when enterprises, faced with having to manage security and identity wirelessly, wanted vendors to converge software-defined WAN and network security functions, such as zero trust, firewall-as-a-service (FWaaS), and cloud access security broker (CASB), into a cloud service.

                          SSE emerged during the pandemic, essentially ditching the SD-WAN functions and unifying CASB, zero trust, and secure web gateway (SWG) into a service. Microsoft is coming into this space late, with vendors like Cisco, Zscaler, and Palo Alto Networks, among others, already a year or two ahead.

                          However, Microsoft’s sheer gravitational pull will help it gain market share, as shown by the drop in share prices of Cloudflare, Palo Alto, and Zscaler right after Microsoft announced its SSE move. ®

                          Tags: Microsoft'sSecurity
                          ">
                          Ferhan Rana

                          Ferhan Rana

                          Related Posts

                          Critical SolarWinds Web Help Desk bug under attack
                          Technology

                          Critical SolarWinds Web Help Desk bug under attack

                          by Ferhan Rana
                          February 4, 2026
                          Rise of AI means companies could pass on SaaS
                          Technology

                          Rise of AI means companies could pass on SaaS

                          by Ferhan Rana
                          February 4, 2026
                          Trump Announces Minerals Stockpile Way Too Late for It to Spare Him From Embarrassment by China
                          Technology

                          Trump Announces Minerals Stockpile Way Too Late for It to Spare Him From Embarrassment by China

                          by Ferhan Rana
                          February 3, 2026
                          SpaceX and xAI Are Merging Into a Very Silly-Sounding Conglomerate. Take It Seriously
                          Technology

                          SpaceX and xAI Are Merging Into a Very Silly-Sounding Conglomerate. Take It Seriously

                          by Ferhan Rana
                          February 3, 2026
                          Steven Spielberg Lands EGOT Status With New Grammy Win
                          Technology

                          Steven Spielberg Lands EGOT Status With New Grammy Win

                          by Ferhan Rana
                          February 2, 2026

                          Premium Content

                          Princess Theodora and Matthew Kumar look so in love in official wedding photos

                          Princess Theodora and Matthew Kumar look so in love in official wedding photos

                          September 29, 2024
                          World of Warcraft‘s Developers Just Made a Huge Leap Forward For Video Game Unionization

                          World of Warcraft‘s Developers Just Made a Huge Leap Forward For Video Game Unionization

                          July 25, 2024
                          Man United vs. Tottenham odds: Free 2025 UEFA Europa League final picks, prediction for Wednesday, May 21

                          Man United vs. Tottenham odds: Free 2025 UEFA Europa League final picks, prediction for Wednesday, May 21

                          May 21, 2025

                          Browse by Category

                          • Business
                          • Crypto
                          • Entertainment
                          • Fashion
                          • Health
                          • Lifestyle
                          • Real Estate
                          • Sports
                          • Technology
                          • Travel
                          • Uncategorized
                          • World

                          Browse by Tags

                          announces Apple Barcelona Beckham Charles Elizabeth Europe Exclusive family First George Google Harry health Inside Intel James Jennifer Kelly Lewis makes Manchester Markle Meghan Michael Microsoft Middleton people Prince Princess Queen REPORT reveals Review Royal Samsung Shares Taylor Trump Twitter wants WATCH William World Years
                          TrivDaily

                          Get the latest World news and analysis, breaking news, features and special reports from World. Also watch videos from across the Europian continent.

                          Learn more

                          Categories

                          • Business
                          • Crypto
                          • Entertainment
                          • Fashion
                          • Health
                          • Lifestyle
                          • Real Estate
                          • Sports
                          • Technology
                          • Travel
                          • Uncategorized
                          • World

                          Browse by Tag

                          Business (1525) Crypto (1593) Entertainment (1947) Fashion (3) Health (1787) Lifestyle (1850) Real Estate (40) Sports (3000) Technology (2979) Travel (1440) Uncategorized (11) World (23)

                          Recent Posts

                          • Arlington SX Full Race Day and TV Broadcast Schedules
                          • Jordon Smith Set for Season, 450SX Debut at Arlington SX
                          • UK Online Casino: A Modern Guide

                          © 2021 TrivDaily - Developed by ADSA Solutions.

                          Welcome Back!

                          Login to your account below

                          Forgotten Password? Sign Up

                          Create New Account!

                          Fill the forms bellow to register

                          All fields are required. Log In

                          Retrieve your password

                          Please enter your username or email address to reset your password.

                          Log In

                          Add New Playlist

                          • Login
                          • Sign Up
                          • Cart
                          No Result
                          View All Result
                          • Home
                          • Business News
                          • Entertainment News
                          • Lifestyle News
                          • Health News
                          • Tech News
                          • Real Estate News
                          • World News

                          © 2021 TrivDaily - Developed by ADSA Solutions.

                          Are you sure want to unlock this post?
                          Unlock left : 0
                          Are you sure want to cancel subscription?