Full list of permissions required for integrating Azure DevOps and Azure DevOps Server with Xopero ONE.
Required permissions for Azure DevOps and Azure DevOps Server specify the access levels Xopero ONE needs to securely back up and restore your data.
Permissions for Azure DevOps
User access levels
The account used for integration must have an appropriate access level assigned within Azure DevOps:
Basic.
Visual Studio Subscriber — professional or enterprise tier.
GitHub Enterprise — similar to basic.
Stakeholder (not recommended) — this level has limited access and cannot properly protect repositories.
To integrate Azure DevOps with Xopero ONE using OAuth, make sure the account has an administrator role. Otherwise, you may encounter permission errors or find that the approval button is inactive.
When integrating Azure DevOps via OAuth, the following scopes are required:
The ability to authorize the Xopero ONEOAuth application depends on your organization's User consent settings within Azure DevOps. The following options are available:
Consent policy
Authorization requirement
To ensure both backup and restore operations succeed, the following permissions are required:
Organization level:
General:
Create new projects (restore)
For on-premise installations, use the personal access token (PAT) method.
Projects and Teams: read, write and manage (vso.project_manage)
Extensions: read
Boards:
Create process (restore)
Edit process (restore)
Project level:
General:
View project-level information (backup)
Repositories level:
Create branch (restore)
Create repository (restore)
Read (backup)
Extensions: read
Allow user consent for apps from verified publishers, for selected permissions
Any user can authorize the app, provided that all requested permissions are classified as low impact by your administrator.
Do not allow user consent
Only users with the Application Administrator or Global Administrator role can authorize the integration.
Let Microsoft manage your consent settings (Recommended)
Authorization is subject to Microsoft's current security guidelines. While this currently allows for Xopero ONE integration, availability may change based on Microsoft's evolving policies.
Xopero ONE can only protect projects that the integrated user account has explicit access to.
OAuth integration
Xopero supports only organizational accounts (Microsoft Entra ID) — personal accounts are not supported. For private accounts, use PAT instead.
Installation permissions for OAuth
Personal Access Token (PAT) integration
Prerequisites:
Required scopes:
When performing a backup with minimal permissions, some metadata might be excluded. To ensure complete protection, select the permissions based on your data protection needs. Note that with read-only permissions, backups can be made, but restoring requires a new token or password with write access.
Granular permission settings
Permissions for Azure DevOps Server
Personal Access Token (PAT) integration
Prerequisites:
Required scopes:
When performing a backup with minimal permissions, some metadata might be excluded. To ensure complete protection, select the permissions based on your data protection needs. Note that with read-only permissions, backups can be made, but restoring requires a new token or password with write access.