{"id":22525,"date":"2021-12-21T11:58:15","date_gmt":"2021-12-21T11:58:15","guid":{"rendered":"https:\/\/aidanfinn.com\/?p=22525"},"modified":"2021-12-21T11:58:15","modified_gmt":"2021-12-21T11:58:15","slug":"azure-firewall-devsecops-in-azure-devops","status":"publish","type":"post","link":"https:\/\/aidanfinn.com\/?p=22525","title":{"rendered":"Azure Firewall DevSecOps in Azure DevOps"},"content":{"rendered":"<p>In this post, I will share the details for granting the least-privilege permissions to GitHub action\/DevOps pipeline service principals for a DevSecOps continuous deployment of Azure Firewall.<\/p>\n<h2>Quick Refresh<\/h2>\n<p>I wrote about the design of the solution and shared the code in my post, <a href=\"https:\/\/aidanfinn.com\/?p=22495\" target=\"_blank\" rel=\"noopener\">Enabling DevSecOps with Azure Firewall<\/a>. There I explained how you could break out the code for the rules of a workload and manage that code in the repo for the workload. Realistically, you would also need to break out the gateway subnet route table user-defined route (legacy VNet-based hub) and the VNet peering connection. All the code for this is <a href=\"https:\/\/github.com\/aidanfinn\/SharedAzureFirewall\/tree\/main\/BicepDevSecOps\" target=\"_blank\" rel=\"noopener\">shared on GitHub<\/a> &#8211; I did update the repo with some structure and with working DevOps pipelines.<\/p>\n<h2>This Update<\/h2>\n<p>There were two things I wanted to add to the design:<\/p>\n<ul>\n<li>Detailed permissions for the service principal used by the workload DevOps pipeline, limiting the scope of change that is possible in the hub.<\/li>\n<li>DevOps pipelines so I could test the above.<\/li>\n<\/ul>\n<h2>The Code<\/h2>\n<p>You&#8217;ll find 3 folders in the Bicep <a href=\"https:\/\/github.com\/aidanfinn\/SharedAzureFirewall\/tree\/main\/BicepDevSecOps\" target=\"_blank\" rel=\"noopener\">code<\/a> now:<\/p>\n<ul>\n<li><strong>hub<\/strong>: This deploys a (legacy) VNet-based hub with Azure Firewall.<\/li>\n<li><strong>customRoles<\/strong>: 4 Azure custom roles are defined. This should be deployed after the hub.<\/li>\n<li><strong>spoke1<\/strong>: This contains the code to deploy a skeleton VNet-based (spoke) workload with updates that are required in the hub to connect the VNet and route ingress on-prem traffic through the firewall.<\/li>\n<\/ul>\n<h2>DevOps Pipelines<\/h2>\n<p>The hub and spoke1 folders each contain a folder called .pipelines. There you will find a .yml file to create a DevOps pipeline.<\/p>\n<p>The DevOps pipeline uses Azure CLI tasks to:<\/p>\n<ul>\n<li>Select the correct Azure subscription &amp; create the resource group<\/li>\n<li>Deploy each .bicep file.<\/li>\n<\/ul>\n<p>My design uses 1 sub for the hub and 1 sub for the workload. You are not glued to this bu you would need to make modifications to how you configure the service principal permissions (below).<\/p>\n<p>To use the code:<\/p>\n<ol>\n<li>Create a repo in DevOps for (1 repo) hub and for (1 repo) spoke1 and copy in the required code.<\/li>\n<li>Create service principals in Azure AD.<\/li>\n<li>Grant the service principal for hub owner rights to the hub subscription.<\/li>\n<li>Grant the service principal for the spoke owner rights to the spoke subscription.<\/li>\n<li>Create ARM service connections in DevOps settings that use the service principals. Note that the names for these service connections are referred to by azureServiceConnection in the pipeline files.<\/li>\n<li>Update the variables in the pipeline files with subscription IDs.<\/li>\n<li>Create the pipelines using the .yml files in the repos.<\/li>\n<\/ol>\n<p>Don&#8217;t do anything just yet!<\/p>\n<h2>Service Principal Permissions<\/h2>\n<p>The hub service principal is simple &#8211; grant it owner rights to the hub subscription (or resource group).<\/p>\n<p><a href=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2021\/12\/Service-Principal-Permissions-Expanded.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-22534\" src=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2021\/12\/Service-Principal-Permissions-Expanded.png\" alt=\"\" width=\"600\" height=\"340\" srcset=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2021\/12\/Service-Principal-Permissions-Expanded.png 956w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2021\/12\/Service-Principal-Permissions-Expanded-300x170.png 300w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2021\/12\/Service-Principal-Permissions-Expanded-768x435.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/p>\n<p>The workload is where the magic happens with this DevSecOps design. The workload updates the hub suing code in the workload repo that affects the workload:<\/p>\n<ul>\n<li>Ingress route from on-prem to the workload in the hub GatewaySubnet.<\/li>\n<li>The firewall rules for the workload in the hub Azure Firewall (policy) using a rules collection group.<\/li>\n<li>The VNet peering connection between the hub VNet and the workload VNet.<\/li>\n<\/ul>\n<p>That could be deployed by the workload DevOps pipeline that is authenticated using the workload&#8217;s service principal. So that means the workload service principal must have rights over the hub.<\/p>\n<p>The quick solution would be to grant contributor rights over the hub and say &#8220;we&#8217;ll manage what is done through code reviews&#8221;. However, a better practice is to limit what can be done as much as possible. That&#8217;s what I have done with the <a href=\"https:\/\/github.com\/aidanfinn\/SharedAzureFirewall\/tree\/main\/BicepDevSecOps\/customRoles\" target=\"_blank\" rel=\"noopener\">customRoles folder<\/a> in my GitHub share.<\/p>\n<p>Those custom roles should be modified to change the possible scope to the subscription ID (or even the resource group ID) of the hub deployment. There are 4 custom roles:<\/p>\n<ul>\n<li><strong>customRole-ArmValidateActionOperator.json<\/strong>: Adds the CUSTOM &#8211; ARM Deployment Operator role, allowing the ARM deployment to be monitored and updated.<\/li>\n<li><strong>customRole-PeeringAdmin.json<\/strong>: Adds the CUSTOM &#8211; Virtual Network Peering Administrator role, allowing a VNet peering connection to be created from the hub VNet.<\/li>\n<li><strong>customRole-RoutesAdmin.json<\/strong>: Adds the CUSTOM &#8211; Azure Route Table Routes Administrator role, allowing a route to be added to the GatewaySubnet route table.<\/li>\n<li><strong>customRole-RuleCollectionGroupsAdmin.json<\/strong>: Adds the CUSTOM &#8211; Azure Firewall Policy Rule Collection Group Administrator role, allowing a rules collection group to be added to an Azure Firewall Policy.<\/li>\n<\/ul>\n<h2>Deploy The Hub<\/h2>\n<p>The hub is deployed first &#8211; this is required to grant the permissions that are required by the workload&#8217;s service principal.<\/p>\n<h2>Grant Rights To Workload Service Principals<\/h2>\n<p>The service principals for all workloads will be added to an Azure AD group (Workloads Pipeline Service Principals in the above diagram). That group is nested into 4 other AAD security groups:<\/p>\n<ul>\n<li><strong>Resource Group ARM Operations<\/strong>: This is granted the CUSTOM &#8211; ARM Deployment Operator role on the hub resource group.<\/li>\n<li><strong>Hub Firewall Policy<\/strong>: This is granted the CUSTOM &#8211; Azure Firewall Policy Rule Collection Group Administrator role on the Azure Firewalll Policy that is associated with the hub Azure Firewall.<\/li>\n<li><strong>Hub Routes<\/strong>: This is granted the CUSTOM &#8211; Azure Route Table Routes Administrator role on the GattewaySubnet route table.<\/li>\n<li><strong>Hub Peering<\/strong>: This is granted the CUSTOM &#8211; Virtual Network Peering Administrator role on the hub virtual network.<\/li>\n<\/ul>\n<h2>Deploy The Workload<\/h2>\n<p>The workload now has the required permissions to deploy the workload and make modifications in the hub to connect the hub to the outside world.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this post, I will share the details for granting the least-privilege permissions to GitHub action\/DevOps pipeline service principals for a DevSecOps continuous deployment of Azure Firewall. Quick Refresh I wrote about the design of the solution and shared the code in my post, Enabling DevSecOps with Azure Firewall. There I explained how you could &hellip; <a href=\"https:\/\/aidanfinn.com\/?p=22525\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Azure Firewall DevSecOps in Azure DevOps&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":22524,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"_wpcom_ai_launchpad_first_post":false,"footnotes":""},"categories":[5],"tags":[488,161,170,383,306,482,489,384,480,386,483,431,80,430,324,190,485],"class_list":["post-22525","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure","tag-action","tag-arm","tag-azure","tag-azure-devops","tag-azure-firewall","tag-bicep","tag-custom-rbac-roles","tag-devops","tag-devsecops","tag-github","tag-iac","tag-infrastructure-as-code","tag-networking","tag-pipeline","tag-routing","tag-security","tag-user-defined-route"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"This post details the DevOps repo pipeline delivery of Azure Firewall with DevSecOps, including the least privilege permissions for the service principals.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"AFinn\"\/>\n\t<meta name=\"google-site-verification\" content=\"TDKjbi2McB2eLIfL6KwPB3aQqv5E-mbcb2QYIcovGaI\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/aidanfinn.com\/?p=22525\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_GB\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Aidan Finn, IT Pro - A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Azure Firewall DevSecOps in Azure DevOps | Aidan Finn, IT Pro\" \/>\n\t\t<meta property=\"og:description\" content=\"This post details the DevOps repo pipeline delivery of Azure Firewall with DevSecOps, including the least privilege permissions for the service principals.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/aidanfinn.com\/?p=22525\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-12-21T11:58:15+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-12-21T11:58:15+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@joe_elway\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Azure Firewall DevSecOps in Azure DevOps | Aidan Finn, IT Pro\" \/>\n\t\t<meta name=\"twitter:description\" content=\"This post details the DevOps repo pipeline delivery of Azure Firewall with DevSecOps, including the least privilege permissions for the service principals.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@joe_elway\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22525#article\",\"name\":\"Azure Firewall DevSecOps in Azure DevOps | Aidan Finn, IT Pro\",\"headline\":\"Azure Firewall DevSecOps in Azure DevOps\",\"author\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/compare-fibre-tiSE_paTt0A-unsplash.jpg\",\"width\":1920,\"height\":1280,\"caption\":\"Photo by Compare Fibre on Unsplash\"},\"datePublished\":\"2021-12-21T11:58:15+00:00\",\"dateModified\":\"2021-12-21T11:58:15+00:00\",\"inLanguage\":\"en-GB\",\"commentCount\":1,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22525#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22525#webpage\"},\"articleSection\":\"Azure, Action, ARM, Azure, Azure DevOps, Azure Firewall, Bicep, Custom RBAC Roles, DevOps, DevSecOps, GitHub, IaC, Infrastructure-as-Code, Networking, Pipeline, Routing, Security, User-Defined Route\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22525#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/aidanfinn.com\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5#listItem\",\"name\":\"Azure\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5#listItem\",\"position\":2,\"name\":\"Azure\",\"item\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22525#listItem\",\"name\":\"Azure Firewall DevSecOps in Azure DevOps\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22525#listItem\",\"position\":3,\"name\":\"Azure Firewall DevSecOps in Azure DevOps\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5#listItem\",\"name\":\"Azure\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\",\"name\":\"AFinn\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22525#personImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"AFinn\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1\",\"name\":\"AFinn\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22525#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"AFinn\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22525#webpage\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22525\",\"name\":\"Azure Firewall DevSecOps in Azure DevOps | Aidan Finn, IT Pro\",\"description\":\"This post details the DevOps repo pipeline delivery of Azure Firewall with DevSecOps, including the least privilege permissions for the service principals.\",\"inLanguage\":\"en-GB\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22525#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/compare-fibre-tiSE_paTt0A-unsplash.jpg\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22525\\\/#mainImage\",\"width\":1920,\"height\":1280,\"caption\":\"Photo by Compare Fibre on Unsplash\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22525#mainImage\"},\"datePublished\":\"2021-12-21T11:58:15+00:00\",\"dateModified\":\"2021-12-21T11:58:15+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#website\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/\",\"name\":\"Aidan Finn, IT Pro\",\"description\":\"A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...\",\"inLanguage\":\"en-GB\",\"publisher\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Azure Firewall DevSecOps in Azure DevOps | Aidan Finn, IT Pro","description":"This post details the DevOps repo pipeline delivery of Azure Firewall with DevSecOps, including the least privilege permissions for the service principals.","canonical_url":"https:\/\/aidanfinn.com\/?p=22525","robots":"max-image-preview:large","keywords":"","webmasterTools":{"google-site-verification":"TDKjbi2McB2eLIfL6KwPB3aQqv5E-mbcb2QYIcovGaI","miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/aidanfinn.com\/?p=22525#article","name":"Azure Firewall DevSecOps in Azure DevOps | Aidan Finn, IT Pro","headline":"Azure Firewall DevSecOps in Azure DevOps","author":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"publisher":{"@id":"https:\/\/aidanfinn.com\/#person"},"image":{"@type":"ImageObject","url":"https:\/\/aidanfinn.com\/wp-content\/uploads\/2021\/12\/compare-fibre-tiSE_paTt0A-unsplash.jpg","width":1920,"height":1280,"caption":"Photo by Compare Fibre on Unsplash"},"datePublished":"2021-12-21T11:58:15+00:00","dateModified":"2021-12-21T11:58:15+00:00","inLanguage":"en-GB","commentCount":1,"mainEntityOfPage":{"@id":"https:\/\/aidanfinn.com\/?p=22525#webpage"},"isPartOf":{"@id":"https:\/\/aidanfinn.com\/?p=22525#webpage"},"articleSection":"Azure, Action, ARM, Azure, Azure DevOps, Azure Firewall, Bicep, Custom RBAC Roles, DevOps, DevSecOps, GitHub, IaC, Infrastructure-as-Code, Networking, Pipeline, Routing, Security, User-Defined Route"},{"@type":"BreadcrumbList","@id":"https:\/\/aidanfinn.com\/?p=22525#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/#listItem","position":1,"name":"Home","item":"https:\/\/aidanfinn.com\/","nextItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=5#listItem","name":"Azure"}},{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=5#listItem","position":2,"name":"Azure","item":"https:\/\/aidanfinn.com\/?cat=5","nextItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?p=22525#listItem","name":"Azure Firewall DevSecOps in Azure DevOps"},"previousItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?p=22525#listItem","position":3,"name":"Azure Firewall DevSecOps in Azure DevOps","previousItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=5#listItem","name":"Azure"}}]},{"@type":"Person","@id":"https:\/\/aidanfinn.com\/#person","name":"AFinn","image":{"@type":"ImageObject","@id":"https:\/\/aidanfinn.com\/?p=22525#personImage","url":"https:\/\/secure.gravatar.com\/avatar\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g","width":96,"height":96,"caption":"AFinn"}},{"@type":"Person","@id":"https:\/\/aidanfinn.com\/?author=1#author","url":"https:\/\/aidanfinn.com\/?author=1","name":"AFinn","image":{"@type":"ImageObject","@id":"https:\/\/aidanfinn.com\/?p=22525#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g","width":96,"height":96,"caption":"AFinn"}},{"@type":"WebPage","@id":"https:\/\/aidanfinn.com\/?p=22525#webpage","url":"https:\/\/aidanfinn.com\/?p=22525","name":"Azure Firewall DevSecOps in Azure DevOps | Aidan Finn, IT Pro","description":"This post details the DevOps repo pipeline delivery of Azure Firewall with DevSecOps, including the least privilege permissions for the service principals.","inLanguage":"en-GB","isPartOf":{"@id":"https:\/\/aidanfinn.com\/#website"},"breadcrumb":{"@id":"https:\/\/aidanfinn.com\/?p=22525#breadcrumblist"},"author":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"creator":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"image":{"@type":"ImageObject","url":"https:\/\/aidanfinn.com\/wp-content\/uploads\/2021\/12\/compare-fibre-tiSE_paTt0A-unsplash.jpg","@id":"https:\/\/aidanfinn.com\/?p=22525\/#mainImage","width":1920,"height":1280,"caption":"Photo by Compare Fibre on Unsplash"},"primaryImageOfPage":{"@id":"https:\/\/aidanfinn.com\/?p=22525#mainImage"},"datePublished":"2021-12-21T11:58:15+00:00","dateModified":"2021-12-21T11:58:15+00:00"},{"@type":"WebSite","@id":"https:\/\/aidanfinn.com\/#website","url":"https:\/\/aidanfinn.com\/","name":"Aidan Finn, IT Pro","description":"A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...","inLanguage":"en-GB","publisher":{"@id":"https:\/\/aidanfinn.com\/#person"}}]},"og:locale":"en_GB","og:site_name":"Aidan Finn, IT Pro - A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...","og:type":"article","og:title":"Azure Firewall DevSecOps in Azure DevOps | Aidan Finn, IT Pro","og:description":"This post details the DevOps repo pipeline delivery of Azure Firewall with DevSecOps, including the least privilege permissions for the service principals.","og:url":"https:\/\/aidanfinn.com\/?p=22525","article:published_time":"2021-12-21T11:58:15+00:00","article:modified_time":"2021-12-21T11:58:15+00:00","twitter:card":"summary","twitter:site":"@joe_elway","twitter:title":"Azure Firewall DevSecOps in Azure DevOps | Aidan Finn, IT Pro","twitter:description":"This post details the DevOps repo pipeline delivery of Azure Firewall with DevSecOps, including the least privilege permissions for the service principals.","twitter:creator":"@joe_elway"},"aioseo_meta_data":{"post_id":"22525","title":null,"description":"This post details the DevOps repo pipeline delivery of Azure Firewall with DevSecOps, including the least privilege permissions for the service principals.","keywords":[],"keyphrases":{"focus":{"keyphrase":"DevSecOps","score":0,"analysis":[]},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":[],"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":{"locations":{"business":{"name":"","businessType":"","image":"","areaServed":"","urls":{"website":"","aboutPage":"","contactPage":""},"address":{"streetLine1":"","streetLine2":"","zipCode":"","city":"","state":"","country":"","addressFormat":"#streetLineOne\n#streetLineTwo\n#city, #state #zipCode"},"contact":{"email":"","phone":"","phoneFormatted":"","fax":"","faxFormatted":""},"ids":{"vat":"","tax":"","chamberOfCommerce":""},"payment":{"priceRange":"","currenciesAccepted":"","methods":""}}},"openingHours":{"useDefaults":true,"show":true,"alwaysOpen":false,"use24hFormat":false,"timezone":"","labels":{"closed":"","alwaysOpen":""},"days":{"monday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"tuesday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"wednesday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"thursday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"friday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"saturday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"sunday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"}}}},"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2021-12-21 11:12:46","updated":"2025-06-04 17:35:03","seo_analyzer_scan_date":null,"focus_keyword":"DevSecOps","additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/aidanfinn.com\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/aidanfinn.com\/?cat=5\" title=\"Azure\">Azure<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAzure Firewall DevSecOps in Azure DevOps\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/aidanfinn.com\/"},{"label":"Azure","link":"https:\/\/aidanfinn.com\/?cat=5"},{"label":"Azure Firewall DevSecOps in Azure DevOps","link":"https:\/\/aidanfinn.com\/?p=22525"}],"amp_enabled":true,"jetpack_featured_media_url":"https:\/\/aidanfinn.com\/wp-content\/uploads\/2021\/12\/compare-fibre-tiSE_paTt0A-unsplash.jpg","_links":{"self":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/22525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=22525"}],"version-history":[{"count":17,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/22525\/revisions"}],"predecessor-version":[{"id":22543,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/22525\/revisions\/22543"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/media\/22524"}],"wp:attachment":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=22525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=22525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=22525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}