Azure DevOps
Azure DevOps Services (cloud) or Azure DevOps Server (on-prem)
Access mode: Read-only
Required information
| Field | Details |
|---|---|
| Organization URL | https://dev.azure.com/<org> or on-prem URL. |
| Project(s) | Azure DevOps project names. |
| Repository names | Specific repos within each project. |
| Authentication | PAT (most common), service principal with OAuth, or SSH key. |
| Access scope | Code (Read). Packaging (Read) if artifact feeds needed. |
Network considerations
Azure DevOps Services: HTTPS over 443 to dev.azure.com.
Azure DevOps Server (on-prem): VPN or standard on-prem access.
Conditional Access: If Azure AD tenant enforces CA policies on DevOps, service principal must comply.
Credential and auth management
Preferred: Service Principal OAuth. Register Azure AD app, grant DevOps org access, use client credentials flow. Most robust for automation.
Acceptable: PAT. Scoped to org and permissions. 1-year max expiry.
SSH keys: Only for direct git clone, not API access.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Authentication | GET /_apis/projects?api-version=7.0 | 200 with project list |
| Repo access | GET /<project>/_apis/git/repositories | Lists repos |
| Code read | GET /<project>/_apis/git/repositories/<repo>/items?path=/ | Lists root contents |
| Commit history | GET /<project>/_apis/git/repositories/<repo>/commits?$top=1 | Returns latest commit |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.