如何阻止Visual Studio Online团队成员重新分配任务及修改任务状态?
Great question! It’s totally normal to want tighter control over who can edit or reassign tasks that aren’t theirs—let’s break down the most effective strategies to lock this down:
1. Fine-Tune Default Security Group Permissions
By default, the Contributors group has broad access to edit all work items in your project. You can dial this back to restrict members to only their own tasks:
- Navigate to your project Settings > Security > Permissions
- Select the group your team members belong to (e.g., the default
Contributorsgroup) - Scroll to the Work Items section and adjust these key permissions:
- Set Edit work items assigned to me to Allow (lets members edit tasks assigned to them)
- Set Edit work items that I created to Allow (if you want creators to manage their own user stories/tasks)
- Set Modify work items to Deny (blocks editing of work items they don’t own or didn’t create)
- Set Assign work items to Deny (prevents reassigning tasks to others; if you still want them to assign tasks to themselves, enable Assign work items to me instead)
2. Create Custom Security Groups for Granular Control
If you have different team tiers (e.g., junior contributors vs. leads/managers), custom groups let you tailor permissions exactly how you need:
- Go to Project Settings > Security > Groups > New Group
- Name it something clear like "Task Assignees" and add your regular team members to it
- Apply the restricted permissions from step 1 to this group, while keeping full edit/assign rights for leads in a separate group (like "Task Managers")
3. Use Workflow Rules to Block Unauthorized State Changes
To specifically stop non-assignees from changing a task’s board status, add a workflow rule to your work item types:
- Head to Project Settings > Work Item Types
- Pick the work item type you want to restrict (e.g., Task, User Story)
- Go to Workflow > Edit
- Add a new rule with these parameters:
- Trigger: When a work item is updated
- Condition: State changes AND Assigned To does not equal Current user
- Action: Block the update with a friendly message like "Only the assigned user can change this task’s status"
4. Test Your Settings to Ensure They Work
Don’t skip this step! Log in with a regular team member’s account and try to:
- Edit a task assigned to someone else
- Reassign a task from another member to yourself
- Change the board state of a task you don’t own
If any of these actions still work, double-check your permission settings—sometimes inheritance from parent groups can override your custom rules, so check the "Inherited Permissions" tab for conflicts.
内容的提问来源于stack exchange,提问作者Frank Odoom

