Microsoft 365: Deploy Without Secrets
Microsoft 365 Dev
Sep 19, 2025 8:30 PM

Microsoft 365: Deploy Without Secrets

by HubSite 365 about Microsoft

Software Development Redmond, Washington

Deploy Microsoft three sixty five SPFx via Azure DevOps and GitHub Actions with Entra ID federated creds, secrets free

Key insights

  • Overview: Martin Lingstuyl demonstrated how to deploy Microsoft 365 artifacts from GitHub Actions and Azure DevOps using Entra ID federated credentials so pipelines run without certificates, secrets, or service accounts.
  • How it works: Register an app in Entra ID, grant minimal permissions, add a federated credential that uses OIDC, and configure a pipeline service connection to obtain short-lived tokens during runs.
  • Deployment flow: Authenticate in the pipeline with the federated credential, then use the Microsoft 365 CLI to push packages and artifacts such as SharePoint Framework solutions, Teams apps, and Power Platform solutions.
  • Security benefits: The secretless model reduces credential leakage risk, removes secret rotation chores, and supports compliance by limiting stored sensitive data in repos and pipelines.
  • Practical tips: Apply least privilege to app permissions, validate federated credential mappings for both GitHub and DevOps, test pipeline runs in a staging branch, and include clear rollback steps.
  • Roadmap and recommendations: Microsoft encourages migration away from classic service connections toward OIDC federated identity to future-proof CI/CD and simplify secure, repeatable deployment pipelines.

Quick summary

Microsoft published a recent demo that shows how teams can deploy Microsoft 365 artifacts from Azure DevOps and GitHub Actions without using certificates or stored secrets. The session, presented by Martin Lingstuyl, walked through app registrations, permissions, and the setup of federated credentials in Entra ID. He then used the CLI for Microsoft 365 to authenticate and push packages in repeatable pipelines. Overall, the video emphasizes a secretless model that reduces credential handling in CI/CD workflows.


How the secretless deployment works

The approach replaces certificates and static secrets with short-lived federated credentials and token-based authentication. Specifically, pipelines exchange a provider-issued token for an identity assertion in Entra ID, which allows the pipeline to act with the app registration's permissions. This method uses native platform features such as the GitHub OIDC token or Azure DevOps service connection federation, so credentials do not live in the repository or variable store. As a result, teams avoid the common risk of exposed secrets while still granting pipelines needed access.


Tools and demonstration highlights

During the demo, Lingstuyl set up an app registration and configured scopes and API permissions to match the deployment needs, then created federated credentials for both GitHub and Azure DevOps. He showed how to use the CLI for Microsoft 365 to authenticate via the federated flow and to push SharePoint Framework and other Microsoft 365 packages from a pipeline. The walkthrough emphasized repeatability and how the same pattern works across repositories and projects, which simplifies maintenance. Importantly, he also explained how to scope permissions narrowly to follow least-privilege principles.


Benefits and practical tradeoffs

This pattern clearly improves security by eliminating long-lived secrets and reducing the blast radius if a pipeline is compromised. Moreover, it simplifies secret rotation and lowers operational overhead, which boosts developer productivity and reduces human error. However, the secretless model introduces tradeoffs because it relies on correct federation setup and precise permission management, which can be complex for teams new to Entra ID or OIDC concepts. Therefore, while it reduces credential exposure, it raises the bar for identity configuration and auditing practices.


Challenges and limitations to consider

One practical challenge is troubleshooting federated token exchanges when they fail, because the error paths often span multiple services and logs. Another limitation is that not all legacy tools and scripts support federated authentication out of the box, so migration may require code changes or wrapper scripts. In addition, operations teams must keep strong governance to ensure app registrations do not accumulate overly broad permissions, and they must monitor token use closely through logging and alerts. Finally, users should account for different token lifetimes and refresh behaviors that can affect pipeline timing and retries.


Advice for adoption and next steps

Teams interested in this pattern should start with a small proof of concept that covers a single repository and a limited deployment target, and then extend the pattern as confidence grows. When shifting to federated credentials, implement clear naming, granular permissions, and automated auditing so teams can track which pipelines hold which federated relationships. Also, document the federation and app registration steps, and include rollback paths in case an identity change breaks a release pipeline. By taking an incremental approach, teams can gain security benefits while managing the operational and learning costs of the transition.


Conclusion

The YouTube demo by Microsoft and Martin Lingstuyl presents a practical path toward secretless deployments for Microsoft 365 artifacts using Azure DevOps, GitHub Actions, and Entra ID federated credentials. It highlights clear security and maintenance benefits, while also calling attention to configuration complexity and governance needs. As a result, organizations should weigh the improved safety against the effort required to rework identity configurations and monitoring. Ultimately, this approach aligns with broader trends in cloud-native security and offers a compelling option for modern DevOps teams.

Microsoft 365 Dev - Microsoft 365: Deploy Without Secrets

Keywords

Deploy Microsoft 365 artifacts Azure DevOps,Microsoft 365 deployment without certificates or secrets,Azure DevOps GitHub certificate-less deployment,GitHub Actions Microsoft 365 no secrets,Azure AD workload identity federation,Managed identities Microsoft 365 deployment,Passwordless CI/CD Microsoft 365,CI/CD Microsoft 365 artifacts automation