如何通过Azure DevOps REST API分配项目管理员及更改项目所有者?
Got it, let's break down how to tackle both your requirements using Azure DevOps REST APIs—since you already checked UserEntitlements and Project APIs but need clear steps, I'll focus on the exact endpoints and workflows you need:
1. Change Project Owner
The Project API is the right tool here, as the project owner is a core property of the project resource. Here's the step-by-step:
- Required Permissions: You must be an Organization Administrator or the current Project Owner to run this.
- Endpoint: Use the
Update ProjectPATCH endpointPATCH https://dev.azure.com/{organization}/_apis/projects/{projectId}?api-version=7.1-preview.3 - Request Body: Include the existing project name/description (to avoid overwriting) plus the target owner's ID:
{ "name": "YourExistingProjectName", "description": "YourProjectDescription (keep or update as needed)", "owner": { "id": "target-user-unique-id" } } - How to get the user ID: Use the Graph API's
List Usersendpoint to fetch the ID for your target user:
Look for theGET https://vssps.dev.azure.com/{organization}/_apis/graph/users?api-version=7.1-preview.1&searchFilter=General&value={target-username-or-email}idfield in the response.
2. Assign a Project Administrator
Project-level admins are managed via the project's built-in "Project Administrators" security group (not UserEntitlements, which handles organization-level access). Here's how to add a user to this group:
Step 1: Get the Project Administrators Group ID
First, fetch the security group descriptor or ID for your project's admins:
GET https://dev.azure.com/{organization}/{project}/_apis/security/groups?api-version=7.1-preview.2
Look for the group with displayName: "Project Administrators" and note its descriptor or id field.
Step 2: Add the User to the Group
Use the security group's Add Member endpoint to add your target user:
POST https://dev.azure.com/{organization}/{project}/_apis/security/groups/{group-descriptor}/members?api-version=7.1-preview.2
Request Body: Include the user's descriptor (from the Graph API users endpoint mentioned earlier):
{ "descriptor": "user-descriptor-from-graph-api" }
- Alternative: If you prefer using role assignments directly, you can use the
Create Role Assignmentendpoint for the project scope, but adding to the built-in admin group is the most straightforward way.
Key Notes
- User Prerequisite: The target user must already have access to your Azure DevOps organization. If not, use the UserEntitlements API's
Create User Entitlementendpoint to add them first (assign at least a "Basic" access level). - Authorization: All requests require a valid Personal Access Token (PAT) with permissions like
Project Management (Read & Write)andSecurity (Read & Write). - Testing: Use Azure DevOps' built-in API test console (accessible via your organization's API documentation page) to test endpoints without writing code.
内容的提问来源于stack exchange,提问作者Deepika Adike

