You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用VSTS CALs访问本地部署的TFS服务器?

Using VSTS CALs to Access On-Premises TFS Server

Got it, let’s walk through exactly how to get your VSTS (now Azure DevOps Services) Basic users accessing your local TFS server—this is a common pitfall when mixing cloud licenses with on-prem tools, so I’ll break down the steps clearly.

Key Background First

First, it’s important to confirm: VSTS CALs are valid for on-premises TFS, but only if your TFS version supports Azure Active Directory (Azure AD) integration. This starts with TFS 2017 and later versions, since that’s when Microsoft added native Azure AD support to on-prem TFS.

If you’re running an older TFS version, you’ll need to upgrade first—there’s no way to map VSTS CALs to pre-2017 TFS instances using Azure AD identities.

Step 1: Integrate TFS with Your Azure AD Tenant

Your VSTS users are tied to your Azure AD tenant, so local TFS needs to trust that tenant to recognize those users. Here’s how to set this up:

  • Open the TFS Administration Console on your application tier server.
  • Navigate to Application Tier > Authentication.
  • Select Azure Active Directory as the identity provider, then follow the setup wizard:
    • Enter your Azure AD tenant ID (you can find this in the Azure Portal under Azure AD > Properties).
    • Register TFS as an application in your Azure AD tenant (the wizard will guide you through creating the app registration and setting the correct callback URLs).
    • Complete the wizard to save the configuration—TFS will now trust identities from your Azure AD tenant.

Step 2: Add VSTS Users to TFS Security Groups

Once Azure AD integration is live, you need to grant your VSTS Basic users access to TFS:

  • Open your TFS web portal, go to Project Settings > Security.
  • Click Add users and enter the Azure AD email addresses of your VSTS users (these are the same emails you used to create their VSTS Basic accounts).
  • Assign the appropriate permission level—for VSTS Basic users, map this to TFS’s Basic access level (this aligns with the CAL permissions you’ve purchased).

Step 3: Log In to TFS with VSTS Credentials

Now your users should be able to log in to local TFS using their VSTS (Azure AD) credentials:

  • For the TFS web portal: When prompted to log in, select Azure Active Directory as the authentication method, then enter their email and password.
  • For Visual Studio or other TFS clients: In the connection dialog, choose Azure Active Directory as the authentication type, then enter their Azure AD email. If you run into credential issues, clear old TFS credentials from Windows Credential Manager (search for "Credential Manager" in Windows, go to Windows Credentials, and delete any entries related to your TFS server).

Step 4: Verify License Mapping

To ensure everything is working correctly:

  • Open the TFS Administration Console, go to Application Tier > Licensing.
  • You’ll see a list of users with access to TFS—confirm that your VSTS users are listed with the Basic access level, and that the license is mapped to your VSTS subscription.

Why Your Initial Attempt Failed

The reason your VSTS user couldn’t log in before is that local TFS was likely using default Windows authentication, which doesn’t recognize Azure AD identities. By integrating TFS with your Azure AD tenant, you’re telling TFS to trust those cloud-based user accounts, which lets you leverage your VSTS CALs for on-prem access.

内容的提问来源于stack exchange,提问作者Ram Datla

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:20:15