You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在不授予全仓库权限的情况下连接Azure DevOps与GitHub?

How to Restrict Azure DevOps Access to Specific GitHub Repositories

Great question! The default broad permissions when linking Azure DevOps to GitHub are definitely overkill for most use cases. Here's a step-by-step guide to narrow it down to only the repositories you need:

Step 1: Revoke Existing Broad Permissions (If Already Granted)

If you’ve already authorized Azure DevOps with full repository access, start by revoking that first:

  • Go to your GitHub account settings
  • Navigate to Applications > Authorized OAuth Apps
  • Find Azure DevOps in the list, click on it
  • Click the Revoke button to remove the existing broad authorization

Step 2: Re-Authorize with Select Repository Permissions

Now set up a new, restricted authorization from Azure DevOps:

  • Open your Azure DevOps project
  • Go to Project Settings > Service Connections
  • Click New service connection and select GitHub
  • Instead of clicking the default Authorize button, look for the option labeled Grant select permissions (this is the key part to avoid full access)
  • You’ll be redirected to GitHub’s authorization page:
    • Under the Repository access section, select Only select repositories
    • Check the box next to each specific repository you want Azure DevOps to access
    • Click Save to confirm the restricted permissions
  • Finish creating the service connection in Azure DevOps

Step 3: Verify the Restricted Permissions

Double-check to make sure the permissions are correctly applied:

  • Go back to GitHub’s Authorized OAuth Apps page
  • Select Azure DevOps again
  • Under Permissions, you’ll see that repository access is limited to the specific repos you selected, instead of "All repositories"

Quick Notes

  • If you have an existing service connection that uses broad permissions, it’s easier to delete it and create a new one with restricted access rather than trying to modify the existing authorization
  • Make sure your Azure DevOps pipelines or tasks only interact with the repositories you’ve granted access to—this avoids permission errors down the line

内容的提问来源于stack exchange,提问作者Andy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 06:29:43