A service connection is Azure DevOps' mechanism for storing credentials that pipelines use to reach external systems — Azure subscriptions, container registries, third-party APIs. Any pipeline authorized to use a connection can act with its full permissions, which makes service connections deployment credentials wearing a friendly UI.
The governance pitfalls
- 'Grant access to all pipelines' — one checkbox turns a scoped credential into an organization-wide one.
- Connections created per team, with nobody inventorying scope or ownership.
- Stored secrets that outlive rotation policies because nothing tracks them.
- Security integrations whose own connections silently break — or silently over-permission.
What good looks like
Inventory every connection and its pipeline grants; prefer workload identity federation over stored secrets; alert on broad grants; and keep the connections your security tooling depends on synchronized and monitored, so a rename or re-scope does not silently sever scanning.

