Appropriate access levels
Recommend appropriate access levels
Access levels and permissions are separate controls evaluated together. Access levels determine which web-portal features a user can access. Permissions determine which actions they may perform on the objects they can reach. Increasing an access level does not itself grant repository permission.
Azure DevOps access levels
| Level | Gets |
|---|---|
| Stakeholder | Unlimited free access. Work items, backlogs, dashboards, and Azure Pipelines feature access, including release viewing and approval; no Repos in private projects |
| Basic | Repos, Pipelines, Boards, and Artifacts, subject to permissions. The first five users are free; the sixth and later users are paid unless another qualifying entitlement applies |
| Basic + Test Plans | Basic plus test management |
| Visual Studio subscriber | Access through the subscription entitlement |
Stakeholder fits a product owner who tracks a backlog or approves a release but does not need private-project Repos access. Existing public projects are a temporary exception: Stakeholders currently have full Repos access there. New public projects cannot be created, and existing public projects are scheduled to convert to private projects in 2027. Basic enables Repos features; repository permissions still determine actual code access.
GitHub
Use an outside collaborator when a contractor or partner needs selected organization repositories without becoming an organization member. Outside collaborators cannot join teams. With Enterprise Managed Users, this role is called repository collaborator.
Reviewing regularly
Use Microsoft Entra group rules to assign access levels where practical. Azure DevOps adjusts a user's access level when they leave the group. Regularly review the Group rules tab so assignments continue to match current needs.
Primary sources
- https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/az-400
- https://learn.microsoft.com/en-us/azure/devops/organizations/security/stakeholder-access?view=azure-devops
- https://learn.microsoft.com/en-us/azure/devops/organizations/security/access-levels?view=azure-devops
- https://learn.microsoft.com/en-us/azure/devops/organizations/billing/buy-basic-access-add-users?view=azure-devops
- https://learn.microsoft.com/en-us/azure/devops/organizations/security/about-permissions?view=azure-devops
- https://learn.microsoft.com/en-us/azure/devops/organizations/accounts/assign-access-levels-by-group-membership?view=azure-devops
- https://learn.microsoft.com/en-us/azure/devops/organizations/projects/public-projects-retirement?view=azure-devops
- https://docs.github.com/en/organizations/managing-user-access-to-your-organizations-repositories/managing-outside-collaborators/adding-outside-collaborators-to-repositories-in-your-organization
- https://docs.github.com/en/enterprise-cloud@latest/organizations/managing-peoples-access-to-your-organization-with-roles/roles-in-an-organization