- Use Azure Key Vault / pipeline secrets- Do NOT hardcode credentials- Use managed identity if possible
- Run on demand (post-deploy) or scheduled (nightly)- Post-deploy recommended for now
by NiX