Connect Azure DevOps
Connect an Azure DevOps organization to Prodgator by signing in with Microsoft Entra ID, or with a personal access token when the organization cannot use Entra sign-in.
Prodgator connects to Azure DevOps through Microsoft Entra ID. If your organization cannot use Entra sign-in, such as one that uses personal Microsoft accounts, connect with a personal access token instead. With Entra, you sign in with your work or school account, pick an organization, and Prodgator creates the service hooks that send Azure Pipelines and Azure Repos events.
Requirements
- An Azure DevOps organization connected to Microsoft Entra ID. Organizations that use personal Microsoft accounts connect with a personal access token instead.
- On Azure DevOps: membership in the organization, and Project Administrator on the projects Prodgator should watch (service hooks need it).
- In Prodgator: the role.
Connect an organization
- Open Admin Console > Integrations.
- On the Azure DevOps card, click Connect Azure DevOps.
- Sign in with your work or school account and accept the permissions Prodgator asks for.
- Pick the organization to connect. If it belongs to another Microsoft Entra tenant than the one you signed in to, Prodgator asks you to sign in to that tenant.
The service hooks Prodgator creates
For each project in the organization (up to 100 when you connect), Prodgator creates nine service hooks, each posting to :
| Publisher | Events |
|---|---|
| Pipelines | Run state changed, stage state changed, job state changed, approval pending, approval completed |
| Azure Repos | Pull request created, pull request updated, pull request merged, code pushed |
Azure DevOps cannot sign deliveries, so each hook sends a secret that Prodgator generated for this connection as the Basic authentication password. Prodgator refuses a delivery whose secret or organization does not match. See the Azure Pipelines adapter for the details.
You can see them under Project settings > Service hooks. Prodgator adds hooks to up to 100 projects when you connect. Its next background pass adds them to projects created later, up to 200 projects per connection.
What you see
Azure Pipelines runs show on Pipelines with their stages and jobs, deployments to environments show on Gates, and Azure Repos pull requests show on Pull Requests. Next steps:
- Protect an environment with the Prodgator gate, so deployments wait for Prodgator.
- Gate pull requests with the same policies as on the other providers.
- Send run reports from your pipelines.
If the person who connected leaves
The connection acts with the access of the person who connected it. If that person leaves the organization or the Microsoft Entra directory, or revokes Prodgator's access, Prodgator can no longer read the organization: new runs stop arriving and pull request statuses are refused. An admin connects the organization again from Admin Console > Integrations, with an account that is a member of it.
Disconnect
Click the delete icon next to the organization in Admin Console > Integrations. Prodgator deletes its service hooks, revokes its access where Microsoft allows it and removes its stored secrets. Two things stay in Azure DevOps. Remove them by hand if you set up the Prodgator gate:
- the Generic service connection named Prodgator, under Project settings > Service connections;
- the Prodgator gate check on each protected environment, under the environment's Approvals and checks. With the connection gone, the check can no longer be answered, so remove it or deployments to that environment wait on it.
To take Prodgator out of your Microsoft account, remove it at .
Troubleshooting
When Microsoft stops the sign-in, Prodgator shows Microsoft's error code (for example ). The sections below cover the common ones.
Tenant not set up for Azure DevOps
Error or : "The app is trying to access a service ... (Azure DevOps) that your organization ... lacks a service principal for."
Your Microsoft Entra tenant has no service principal for Azure DevOps, so no app can ask for Azure DevOps access there yet. An administrator of the tenant (Application Administrator, Cloud Application Administrator or Global Administrator) adds it once.
With the Azure CLI, signed in to that tenant:
az login --tenant <your tenant id or domain>
az ad sp create --id 499b84ac-1321-427f-aa17-267ca6975798Or with Microsoft Graph PowerShell:
Connect-MgGraph -TenantId <your tenant id or domain> -Scopes "Application.ReadWrite.All"
New-MgServicePrincipal -AppId 499b84ac-1321-427f-aa17-267ca6975798is Microsoft's own application id for Azure DevOps. Then connect again from Admin Console > Integrations.
Sign in to Prodgator's Connect Azure DevOps with an account from the same Microsoft Entra directory the Azure DevOps organization is connected to. You can see that directory in Azure DevOps under Organization settings > Microsoft Entra.
"Insufficient privileges", even for the only user. If either command fails this way, the tenant may be an unmanaged (self-service) directory with no Global Administrator. Microsoft creates these when someone signs up for a Microsoft service with a work email and no one has taken over the domain. To fix it, either:
- Take over the directory as its admin: in the Microsoft 365 admin center, choose Become the admin and verify the domain with a DNS TXT record. Microsoft describes the steps in Admin takeover of an unmanaged directory. Then run the command above as that admin.
- Or connect the Azure DevOps organization to a managed tenant (one with an administrator), and sign in to Prodgator with an account from that tenant.
Administrator approval needed
Errors , or . Your tenant does not let users approve the app themselves. An administrator signs in once through Connect Azure DevOps and accepts the permissions on behalf of the organization, or approves your request in the Microsoft Entra admin center under Enterprise applications > Admin consent requests.
Wrong account
Errors or . The account you signed in with is not in the tenant, or it is a personal Microsoft account. Sign in with a work or school account from the directory your Azure DevOps organization is connected to.
Nothing to connect
Microsoft accepted the sign-in, but none of your Azure DevOps organizations can be connected. Check that the organization is connected to Microsoft Entra ID (Organization settings > Microsoft Entra) and that you are a member of it.