Lesson294 words

Appropriate access levels

Recommend appropriate access levels

Access levels and permissions are separate controls evaluated together. Access levels determine which web-portal features a user can access. Permissions determine which actions they may perform on the objects they can reach. Increasing an access level does not itself grant repository permission.

Azure DevOps access levels

LevelGets
StakeholderUnlimited free access. Work items, backlogs, dashboards, and Azure Pipelines feature access, including release viewing and approval; no Repos in private projects
BasicRepos, Pipelines, Boards, and Artifacts, subject to permissions. The first five users are free; the sixth and later users are paid unless another qualifying entitlement applies
Basic + Test PlansBasic plus test management
Visual Studio subscriberAccess through the subscription entitlement

Stakeholder fits a product owner who tracks a backlog or approves a release but does not need private-project Repos access. Existing public projects are a temporary exception: Stakeholders currently have full Repos access there. New public projects cannot be created, and existing public projects are scheduled to convert to private projects in 2027. Basic enables Repos features; repository permissions still determine actual code access.

GitHub

Use an outside collaborator when a contractor or partner needs selected organization repositories without becoming an organization member. Outside collaborators cannot join teams. With Enterprise Managed Users, this role is called repository collaborator.

Reviewing regularly

Use Microsoft Entra group rules to assign access levels where practical. Azure DevOps adjusts a user's access level when they leave the group. Regularly review the Group rules tab so assignments continue to match current needs.

Primary sources

Ready to study Designing and Implementing Microsoft DevOps Solutions (AZ-400)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free