Access with Azure Active Directory groups

Azure DevOps Services

Do you want an easier way to control who can access your team's critical resources and key business assets in Azure DevOps Services? If you already use Microsoft services like Microsoft 365 or Azure Active Directory (Azure AD), you can use the same identities with your organization. Azure AD works with your organization to control access and authenticate users.

When you organize directory members with Azure AD groups, you can reuse those groups to manage permissions in bulk for your organization. Add those groups to the group that you want. For example, add them to built-in groups like Project Collection Administrators or Contributors, or manually created groups like your project management team. Azure AD group members inherit permissions from the Azure DevOps group, so you don't have to manage group members one at a time.

Not familiar with Azure AD, but want to check it out? Learn more about Azure AD benefits and differences in how you control organization access with Microsoft accounts or with Azure AD.

Note

Due to a functional limitation on Microsoft Graph, service principals will not appear in any list of Azure AD group members on Azure DevOps. Permissions set on any Azure AD groups will still apply to any service principals in the group that have been added to the organizations, even if they are not displaying on the web UI.

Prerequisites

Add an Azure AD group to an Azure DevOps group

Note

To enable the preview feature, Organization Permissions Settings Page v2, see Enable preview features.

  1. Sign in to your organization (https://dev.azure.com/{yourorganization}).

    Why am I asked to choose between my work or school account and my personal account?

  2. Go to Organization settings.

    Screenshot showing highlighted Organization settings button.

  3. Choose Permissions, and then select the group you want to add a member to.

    Add a member to your selected group

  4. Select Members, and then select Add.

    Select Members, and then Add

    You invite guests into Azure AD and into your Azure AD-backed organizations, without waiting for them to accept. This invitation allows you to add those guests to your organization, grant access to projects, assign extensions, and more.

  5. Add users or groups, and then Save your changes.

    Save add users or groups