You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure CLI设置Azure DevOps Readers组权限遇Token问题求助

Azure DevOps通过Azure CLI配置Readers组权限的Token问题

需求目标

为Azure DevOps中的Readers组自动化配置两项权限:

  • 删除团队项目
  • 编辑项目级信息

当前配置代码(PowerShell+Azure CLI)

$OrgName = ""
$ProName = ""

Write-Host "Project Name is " $ProName -ForegroundColor Green

# 获取Namespace ID
$namespaceId = az devops security permission namespace list --org "https://dev.azure.com/$OrgName/" --query "[?@.name == 'Project'].namespaceId | [0]" -o tsv
Write-Host "Name Space Id is " $namespaceId

# 获取Readers组的descriptor
$GroupName = "Readers"
Write-Host "Group Name is " $GroupName 

$Subject = az devops security group list --org https://dev.azure.com/$OrgName/ --project $ProName --query "graphGroups[?displayName == '$GroupName'].descriptor | [0]" -o tsv
Write-Host "Subject is " $Subject

# 获取编辑项目信息对应的权限bit值(GENERIC_WRITE)
$writeBit = az devops security permission namespace show --namespace-id $namespaceId --org "https://dev.azure.com/$OrgName/" --query "[0].actions[?@.name == 'GENERIC_WRITE'].bit |[0]" -o tsv
Write-Host "GENERIC_WRITE Bit is " $writeBit

# 获取删除项目对应的权限bit值(GENERIC_DELETE)
$deleteBit = az devops security permission namespace show --namespace-id $namespaceId --org "https://dev.azure.com/$OrgName/" --query "[0].actions[?@.name == 'GENERIC_DELETE'].bit |[0]" -o tsv
Write-Host "GENERIC_DELETE Bit is " $deleteBit

# 获取项目ID
$ProjID = az devops project list --org https://dev.azure.com/$OrgName/ --query "value[?name == '$ProName'].id |[0]" -o tsv
Write-Host "Project ID is " $ProjID

# 配置编辑项目信息权限
az devops security permission update --id $namespaceId --subject $Subject --token "vstfs:///Classification/TeamProject/$ProjID" --allow-bit $writeBit --merge true --org "https://dev.azure.com/$OrgName/" -o table

# 配置删除项目权限
az devops security permission update --id $namespaceId --subject $Subject --token "vstfs:///Classification/TeamProject/$ProjID" --allow-bit $deleteBit --merge true --org "https://dev.azure.com/$OrgName/" -o table

# 查看权限条目
az devops security permission show --id $namespaceId --subject $Subject --token "vstfs:///Classification/TeamProject/$ProjID" --org "https://dev.azure.com/$OrgName/" -o table

# 查看该命名空间下所有权限选项及bit值
az devops security permission namespace show --namespace-id $namespaceId --org "https://dev.azure.com/$OrgName/"

遇到的问题

  1. 使用无效随机数字作为Token时,命令能正常执行并返回权限已添加,但实际无任何权限生效
  2. 按照文档拼接$PROJECT:vstfs:///Classification/TeamProject/$ProjID格式的Token时,会生成无效的新Token条目,ADO门户权限页面无变化
  3. 当前权限列表输出:
Token                                                                              Effective Allow    Effective Deny
---------------------------------------------------------------------------------  -----------------  ----------------
$PROJECT:vstfs:///Classification/TeamProject/e648b2f1-b6c8-4c73-8024-xxxxxxxxxxxx  0                  0
$PROJECT:vstfs:///Classification/TeamProject/ede8562f-3c53-4af7-8b2f-xxxxxxxxxxxx  0                  0
$PROJECT:vstfs:///Classification/TeamProject/f11081f7-a109-4969-8ac2-xxxxxxxxxxxx  0                  0
$PROJECT:vstfs:///Classification/TeamProject/f31ed069-717a-4dae-88c5-xxxxxxxxxxxx  0                  0
$PROJECT:vstfs:///Classification/TeamProject/fb881522-23c6-41be-847c-xxxxxxxxxxxx  0                  0
///Classification/TeamProject/78558778                                             0                  0
///Classification/TeamProject/910e9e11-81ea-471b-8ed3-xxxxxxxxxxxx                 0                  0
///Classification/TeamProject/*******shop                                          0                  0
///Classification/TeamProject/e38e6183-e385-4605-96be-xxxxxxxxxxxx                 2                  0

问题解决要点

  1. 正确的Token格式:Project命名空间的有效Token不需要$PROJECT:前缀,直接使用vstfs:///Classification/TeamProject/{ProjectID}即可,从权限列表最后一行的有效条目可以验证这一点(其Effective Allow为2,对应GENERIC_WRITE的bit值)
  2. 修正变量大小写:PowerShell区分大小写,确保代码中$Subject变量的大小写一致,避免因变量未正确赋值导致权限配置失效
  3. 获取正确的权限bit值:
    • 编辑项目级信息对应GENERIC_WRITE,bit值为2
    • 删除团队项目对应GENERIC_DELETE,bit值为4
    • 使用-o tsv参数获取纯bit值,避免az cli返回的字符串带引号导致配置错误
  4. 合并权限配置:使用--merge true参数确保新配置的权限与已有权限合并,而非覆盖

内容的提问来源于stack exchange,提问作者Vishal Thakur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 11:03:25