You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从Azure DevOps REST API响应中排除已删除的用户与组?

How to Exclude Deleted Users/Groups from Azure DevOps REST API Responses

I get it—dealing with stale deleted groups/users cluttering up your Graph API responses is frustrating, especially since the official docs confirm that deleted groups are still returned even if they’ve been removed from the account or have no memberships left. Unfortunately, there’s no built-in filter parameter for this in the current version of the API, and the response payloads don’t include an explicit "deleted" flag to make client-side filtering straightforward.

That said, there are a few workarounds you can use to get a clean set of valid objects:

1. Client-Side Validation via Individual Object Lookups

Even though the list endpoint doesn’t flag deleted items, you can verify each group/user’s validity by making a follow-up call to the individual get endpoint. For example:

  • For groups: GET https://vssps.dev.azure.com/{organization}/_apis/graph/groups/{groupId}?api-version=6.0
  • For users: GET https://vssps.dev.azure.com/{organization}/_apis/graph/users/{userId}?api-version=6.0

If the call returns a 404 Not Found status code, that means the object has been deleted and can be filtered out from your initial response. Just keep in mind this adds extra API calls, so you’ll want to handle rate limits carefully—consider batching requests or adding a short-lived cache to avoid hitting throttling limits.

2. Maintain a Blacklist Using Audit Logs

You can leverage Azure DevOps’ Audit Log API to track deleted users/groups, then use that data to build a local blacklist to filter your Graph API results. Here’s how:

  1. Call the audit log endpoint to fetch delete events:
    GET https://auditservice.dev.azure.com/{organization}/_apis/audit/auditlog?api-version=7.1-preview.1
    
  2. Filter results where category is GroupManagement or UserManagement, and actionName includes Delete. Extract the IDs of deleted objects from these entries.
  3. When you get results from the Graph API, exclude any objects whose IDs match entries in your blacklist.

This approach reduces the number of follow-up calls, but you’ll need to keep your blacklist updated periodically to catch recent deletions.

3. Indirect Validation via Membership Checks (For Groups)

Deleted groups typically won’t have any active memberships left (even if all prior memberships were removed before deletion). You can use the Membership API to check if a group has any valid members:

GET https://vssps.dev.azure.com/{organization}/_apis/graph/memberships/{groupId}?api-version=6.0

If the response returns an empty list or only stale entries, it’s a strong indicator the group is no longer active. Note that this isn’t foolproof—some valid groups might temporarily have no members—so use this as a secondary check alongside other methods.

If you find these workarounds cumbersome, consider submitting a feature request to the Azure DevOps feedback forum. Many API improvements start from community requests, so pushing for an explicit deleted flag or a filter parameter could help solve this issue long-term.

内容的提问来源于stack exchange,提问作者Oleksii

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 21:17:49