Full list of permissions required for integrating Azure DevOps and Azure DevOps Server with Xopero ONE.
The account used for integration must have an appropriate access level assigned within Azure DevOps:
Basic.
Visual Studio Subscriber — professional or enterprise tier.
Learn about API limitations for Azure DevOps & DevOps Server in Xopero ONE.
Rate limits enhance security by preventing an overwhelming number of requests that could disrupt, block, or destabilize the application's functionality—the system enforces these limits for stability. For more information, visit .
In Azure DevOps Server (on-premises), API limits are flexible and depend on server resources and configuration. Unlike the cloud version, there are no fixed, global request limits—administrators set performance parameters and limits tailored to the organization's specific needs.
Unfortunately, unlike other DevOps, Microsoft does not provide information about the exact number of queries that can be sent in a given time period.
Stakeholder (not recommended) — this level has limited access and cannot properly protect repositories.
To integrate Azure DevOps with Xopero ONE using OAuth, make sure the account has an administrator role. Otherwise, you may encounter permission errors or find that the approval button is inactive.
When integrating Azure DevOps via OAuth, the following scopes are required:
The ability to authorize the Xopero ONE OAuth application depends on your organization's User consent settings within Azure DevOps. The following options are available:
Allow user consent for apps from verified publishers, for selected permissions
Any user can authorize the app, provided that all requested permissions are classified as low impact by your administrator.
Do not allow user consent
Only users with the Application Administrator or Global Administrator role can authorize the integration.
Let Microsoft manage your consent settings (Recommended)
To ensure both backup and restore operations succeed, the following permissions are required:
Organization level:
General:
Create new projects (restore)
Boards:
Create process (restore)
Edit process (restore)
Project level:
General:
View project-level information (backup)
Repositories level:
Create branch (restore)
Create repository (restore)
Read (backup)
For on-premise installations, use the personal access token (PAT) method.
Xopero ONE can only protect projects that the integrated user account has explicit access to.
Xopero supports only organizational accounts (Microsoft Entra ID) — personal accounts are not supported. For private accounts, use PAT instead.
When performing a backup with minimal permissions, some metadata might be excluded. To ensure complete protection, select the permissions based on your data protection needs. Note that with read-only permissions, backups can be made, but restoring requires a new token or password with write access.
When performing a backup with minimal permissions, some metadata might be excluded. To ensure complete protection, select the permissions based on your data protection needs. Note that with read-only permissions, backups can be made, but restoring requires a new token or password with write access.
Authorization is subject to Microsoft's current security guidelines. While this currently allows for Xopero ONE integration, availability may change based on Microsoft's evolving policies.

This article explains how to add an Azure DevOps Server organization to Xopero ONE.
Azure DevOps Server (self-managed, on-premise) does not support OAuth and requires a personal access token.
Log in to XMS, open the DevOps tab on the left side of the window, and select Azure DevOps from the list.
Click the Connect button under Azure DevOps Server.
Set your authentication method.
In Authentication, select Azure DevOps Server.
Enter the service address of your Azure DevOps Server (IP or DNS name, including the protocol).
Configure your repository sync and default worker. Specify hours for synchronization, or set a time interval for automatic updates.
Click Proceed to complete adding your Azure DevOps Server organization and grant Xopero ONE access to the specified resources.
Your Azure DevOps Server organization has now been successfully added to Xopero ONE. Click Custom policy to adjust your backup policy settings, or click Run backup to execute the backup immediately using the current policy configuration.
Choose whether Xopero should automatically add new repositories to your backup.
Cloud workers cannot access local network storage. Choose a device with the necessary access if backing up locally.



This article explains how to add an Azure DevOps organization to Xopero ONE.
Log in to XMS, open the DevOps tab on the left side of the window, and select Azure DevOps from the list.
Click the Connect button under Azure DevOps.
, log in with a user account which has the required permissions for the repositories or projects to protect. If your Azure login session is active in a different tab, the login will complete automatically.
Check the Consent on behalf of your organization checkbox and click Accept to proceed.
Your Azure DevOps organization has now been successfully added to Xopero ONE. Click Custom policy to adjust your backup policy settings, or click Run backup to execute the backup immediately using the current policy configuration.
Log in to XMS, open the DevOps tab on the left side of the window, and select Azure DevOps from the list.
Click the advanced mode link under Azure DevOps and Azure DevOps Server tiles.
When adding an organization, you may be prompted to grant additional permissions to the Xopero ONE application — make sure your browser allows Xopero to open pop-up windows.
Depending on your browser, you can either adjust the settings to allow pop-ups or permit the authorization window to open once.

Set your authentication method.
In Authentication, select Azure DevOps.
For Connect using, choose Username and Personal Access Token.
Add or select PAT from the Password Manager.
Choose whether Xopero should automatically add new repositories to your backup.
Configure your repository sync and default worker. Specify hours for synchronization, or set a time interval for automatic updates.
Cloud workers cannot access local network storage. Choose a device with the necessary access if backing up locally.
Click Proceed to complete adding your Azure DevOps organization and grant Xopero ONE access to the specified resources.
Your Azure DevOps organization has now been successfully added to Xopero ONE. Click Custom policy to adjust your backup policy settings, or click Run backup to execute the backup immediately using the current policy configuration.










