-
Notifications
You must be signed in to change notification settings - Fork 0
AzDoAgentPoolPermission
Michael Zanatta edited this page Aug 18, 2026
·
4 revisions
AzDoAgentPoolPermission [string] #ResourceName
{
PoolName = [String]$PoolName
GroupName = [String]$GroupName
[ isInherited = [Boolean]$isInherited ]
[ Permissions = [HashTable[]]$Permissions ]
[ Ensure = [String] {'Present', 'Absent'} ]
}AzDoAgentPoolPermission/Permissions
{
Identity = [String]$Identity # Syntax
# SYNTAX: '[ProjectName | OrganizationName]\ServicePrincipalName, UserPrincipalName, UserDisplayName, GroupDisplayName'
# EXAMPLE: '[TestProject]\UserName@email.com'
# EXAMPLE: '[SampleOrganizationName]\Project Collection Administrators'
Permission = [Hashtable]$Permissions # See 'Permission List'
}AzDoAgentPoolPermission/Permissions/Permission
{
PermissionName|PermissionDisplayName = [String]$Name { 'Allow, Deny' }
}Either 'Name' or 'DisplayName' can be used, but we Strongly Recommend that you use 'Name' in your configuration.
| Name | DisplayName | Values | Note |
|---|---|---|---|
| Use | Use | [ allow, deny ] | |
| Manage | Manage | [ allow, deny ] | Not recommended. |
| Create | Create | [ allow, deny ] | |
| ViewAuthorization | View Authorization | [ allow, deny ] | |
| ManagePermissions | Manage Permissions | [ allow, deny ] | Not recommended. |
- PoolName: The name of the agent pool. This property is mandatory and serves as the key property for the resource.
-
GroupName: The name of the group to grant permissions to. This is a key property. Use the format
[ProjectName]\GroupNameor[TEAM FOUNDATION]\GroupNamefor organization-level groups. -
isInherited: Whether permissions are inherited. Defaults to
$true. - Permissions: A HashTable that specifies the permissions to be set. Refer to: 'Permissions Syntax'.
-
Ensure: Specifies whether the permissions should exist. Valid values are
PresentandAbsent.
This resource manages security permissions on Azure DevOps agent pools, controlling which groups or users can use or administer the pool.
Configuration ExampleConfig {
Import-DscResource -ModuleName 'AzureDevOpsDscNative'
Node localhost {
AzDoAgentPoolPermission AddAgentPoolPermission {
Ensure = 'Present'
PoolName = 'MyPool'
GroupName = '[MyProject]\Contributors'
isInherited = $true
Permissions = @(
@{
Identity = '[MyProject]\Contributors'
Permission = @{
'Use' = 'Allow'
}
}
)
}
}
}
Start-DscConfiguration -Path ./ExampleConfig -Wait -Verbose# Return the current configuration for AzDoAgentPoolPermission
$properties = @{
PoolName = 'MyPool'
GroupName = '[MyProject]\Contributors'
isInherited = $true
Permissions = @(
@{
Identity = '[MyProject]\Contributors'
Permission = @{
'Use' = 'Allow'
}
}
)
}
Invoke-DscResource -Name 'AzDoAgentPoolPermission' -Method Get -Property $properties -ModuleName 'AzureDevOpsDscNative'parameters: {}
variables: {
ProjectName: MyProject,
PoolName: MyPool
}
resources:
- name: Agent Pool Contributors Permission
type: AzureDevOpsDscNative/AzDoAgentPoolPermission
dependsOn:
- AzureDevOpsDscNative/AzDoAgentPool/MyPool
properties:
PoolName: $PoolName
GroupName: '[$ProjectName]\Contributors'
isInherited: true
Permissions:
- Identity: '[$ProjectName]\Contributors'
Permission:
Use: Allow
Ensure: PresentLCM Initialization:
$params = @{
AzureDevopsOrganizationName = "SampleAzDoOrgName"
ConfigurationDirectory = "C:\Datum\DSCOutput\"
ConfigurationUrl = 'https://configuration-path'
JITToken = 'SampleJITToken'
Mode = 'Set'
AuthenticationType = 'ManagedIdentity'
ReportPath = 'C:\Datum\DSCOutput\Reports'
}
Invoke-AzDoLCM @params- Assert-BoundParameter
- Assert-ElevatedUser
- Assert-IPAddress
- Assert-Module
- AzDoAPI_0_ProjectCache
- AzDoAPI_1_GroupCache
- AzDoAPI_2_UserCache
- AzDoAPI_3_GroupMemberCache
- AzDoAPI_4_GitRepositoryCache
- AzDoAPI_5_PermissionsCache
- AzDoAPI_6_ServicePrinciple
- AzDoAPI_7_IdentitySubjectDescriptors
- AzDoAPI_8_ProjectProcessTemplates
- AzDoAPI_9_DevOpsClassificationNodes
- Compare-DscParameterState
- Compare-ResourcePropertyState
- ConvertFrom-DscResourceInstance
- ConvertTo-Base64String
- ConvertTo-CimInstance
- ConvertTo-HashTable
- Find-Certificate
- Format-Path
- Get-AzDevOpsOperation
- Get-AzDevOpsServicesApiUri
- Get-AzDevOpsServicesUri
- AzDoAgentPool
- AzDoAgentPoolPermission
- AzDoAgentQueue
- AzDoAreaNodes
- AzDoAreaPermission
- AzDoArtifactFeed
- AzDoArtifactFeedPermission
- AzDoArtifactFeedSettings
- AzDoArtifactFeedView
- AzDoAuditStream
- AzDoBranchPolicy
- AzDoCheckConfiguration
- AzDoDeploymentGroup
- AzDoEnvironmentApproval
- AzDoEnvironmentPermission
- AzDoExtension
- AzDoGitPermission
- AzDoGitRepository
- AzDoGroupMember
- AzDoGroupPermission
- AzDoIterationNodes
- AzDoIterationPermission
- AzDoNotificationSubscription
- AzDoOrganizationGroup
- AzDoOrganizationSettings
- AzDoPipeline
- AzDoPipelineEnvironment
- AzDoPipelinePermission
- AzDoPipelineSettings
- AzDoProcess
- AzDoProcessPermission
- AzDoProject
- AzDoProjectGroup
- AzDoProjectPermission
- AzDoProjectServices
- AzDoRepositorySettings
- AzDoSecurityNamespacePermission
- AzDoServiceConnection
- AzDoServiceConnectionPermission
- AzDoServiceHook
- AzDoTaskGroup
- AzDoTeam
- AzDoTeamMember
- AzDoTeamSettings
- AzDoUserEntitlement
- AzDoVariableGroup
- AzDoVariableGroupPermission
- AzDoWiki
- AzDoWIPTags