Posts by this author

Apr 23, 2025
Post comments count0
Post likes count2

Spring Cleaning: A CTA for Azure DevOps OAuth Apps with expired or long-living secrets

Today, we officially closed the doors on any new Azure DevOps OAuth app registrations. As we prepare for the end-of-life for Azure DevOps OAuth apps in 2026, we'll begin outreach to engage existing app owners and support them through the migration process to use the Microsoft Identity platform instead for future app development with Azure DevOps. ...

DevOpsSecurity
Mar 26, 2025
Post comments count0
Post likes count1

New Overlapping Secrets on Azure DevOps OAuth

As you may have read, Azure DevOps OAuth apps are due for deprecation in 2026. All developers are encouraged to migrate their applications to use Microsoft Entra ID OAuth, which can access all Azure DevOps APIs and has the added benefit of enhanced security features and long-term investment. Although we are nearing Azure DevOps OAuthโ€™s end-of-life...

Azure & CloudDevOps
Feb 4, 2025
Post comments count2
Post likes count4

Full web support for conditional access policies across Azure DevOps and partner web properties

Weโ€™re happy to announce that weโ€™ve made significant progress in updating our web authentication stack on Azure DevOps services and partner web properties to utilize Microsoft Entra tokens to handle web sessions. By replacing our previous cookies with Entra tokens, weโ€™ve deepened the integration we have with Microsoft Entra ID on our web experience...

Azure & CloudDevOpsUX
Jan 6, 2025
Post comments count8
Post likes count4

Reducing personal access token (PAT) usage across Azure DevOps

In the new year, weโ€™ll be making moves towards strengthening Microsoft and our customers' security posture in regards to the usage and creation of personal access tokens (PATs). If youโ€™ve been following this blog, you may have noticed weโ€™ve been distancing away from PATs as the recommended authentication method for Azure DevOps APIs by offering mo...

Azure & CloudSecurity
Oct 28, 2024
Post comments count4
Post likes count2

No new Azure DevOps OAuth apps beginning April 2025

๐Ÿ“ข As of April 23, 2025, the Azure DevOps OAuth app platform is no longer accepting new app registrations. Starting April 2025, we will no longer accept new registrations of Azure DevOps OAuth apps. This is the first step weโ€™ll be taking towards our longer-term vision of sunsetting the Azure DevOps OAuth platform. Moving forward, weโ€™ll be publi...

Azure & CloudDevOps
Apr 3, 2024
Post comments count3
Post likes count1

End of Support for Microsoft products reliant on older Azure DevOps and Visual Studio authentication

Azure DevOps will no longer guarantee support for older authentication methods in use by out-of-support Visual Studio and Microsoft products. Known impacted clients include: This may not be a comprehensive list of impacted products, but affected products are expected to be out of support already per Microsoftโ€™s product end of su...

Azure & Cloud
Feb 5, 2024
Post comments count1
Post likes count5

Regenerating secrets for Azure DevOps OAuth applications

You can now self-regenerate new client secrets as needed for apps made on top of the Azure DevOps' OAuth platform. A valid, active client secret is critical for getting a refresh token to continue using your app. Once the secret has expired, you will also no longer be able to get access and refresh tokens needed to access Azure Devops APIs through ...

Azure & Cloud
Jan 19, 2024
Post comments count0
Post likes count2

Final notice of alternate credentials deprecation

In November 2019, we announced that the alternate credentials feature will be formally deprecated in March 2020. Since then, a small number of users were grandfathered in with continued usage of existing alternate credentials, which have remained active until today. We will be discontinuing all usage of alternate credentials this month. Users have...

DevOpsSecurity
Sep 28, 2023
Post comments count0
Post likes count2

New Azure DevOps scopes now available for Microsoft Identity OAuth delegated flow apps

We have added new Azure DevOps scopes for delegated OAuth apps on the Microsoft Identity platform, also colloquially known as Azure Active Directory OAuth apps. These new scopes will enable app developers to announce specifically which permissions they are hoping to request from the user in order to perform app duties. They may look familiar as the...

Azure & CloudDevOpsSecurity
Sep 27, 2023
Post comments count7
Post likes count3

Managed identity and service principal support for Azure DevOps now in General Availability (GA)

After announcing the release of Managed Identity and Service Principal support in public preview last March, we were overcome by the positive response many of you had. Weโ€™re grateful to those who have taken the time to implement a managed identity within your apps and tools. With your help, weโ€™ve collected valuable feature feedback and resolved som...

Azure & CloudDevOpsSecurity