-
Notifications
You must be signed in to change notification settings - Fork 0
AzDoServiceConnectionPermission
Michael Zanatta edited this page Aug 19, 2026
·
4 revisions
AzDoServiceConnectionPermission [string] #ResourceName
{
ProjectName = [String]$ProjectName
ConnectionName = [String]$ConnectionName
GroupName = [String]$GroupName
[ isInherited = [Boolean]$isInherited ]
[ Permissions = [HashTable[]]$Permissions ]
[ Ensure = [String] {'Present', 'Absent'} ]
}AzDoServiceConnectionPermission/Permissions
{
Identity = [String]$Identity # Syntax
# SYNTAX: '[ProjectName | OrganizationName]\ServicePrincipalName, UserPrincipalName, UserDisplayName, GroupDisplayName'
# EXAMPLE: '[TestProject]\UserName@email.com'
# EXAMPLE: '[SampleOrganizationName]\Project Collection Administrators'
Permission = [Hashtable]$Permissions # See 'Permission List'
}AzDoServiceConnectionPermission/Permissions/Permission
{
PermissionName|PermissionDisplayName = [String]$Name { 'Allow, Deny' }
}Either 'Name' or 'DisplayName' can be used, but we Strongly Recommend that you use 'Name' in your configuration.
| Name | DisplayName | Values | Note |
|---|---|---|---|
| Use | Use service connection | [ allow, deny ] | |
| Administer | Administer service connection | [ allow, deny ] | Not recommended. |
| Create | Create service connection | [ allow, deny ] | |
| ViewAuthorization | View authorization | [ allow, deny ] | |
| ViewEndpoint | View service connection | [ allow, deny ] |
- ProjectName: The name of the Azure DevOps project. This property is mandatory and serves as a key property for the resource.
- ConnectionName: The name of the service connection. This is a key property.
-
GroupName: The name of the group to grant permissions to. This is a key property. Use the format
[ProjectName]\GroupName. -
isInherited: Whether permissions are inherited. Defaults to
$true. - Permissions: A HashTable that specifies the permissions to be set. Refer to: 'Permissions Syntax'.
-
Ensure: Specifies whether the permissions should exist. Valid values are
PresentandAbsent.
This resource manages security permissions on Azure DevOps service connections, controlling which groups or users can use or manage specific service connections in pipelines.
Configuration ExampleConfig {
Import-DscResource -ModuleName 'AzureDevOpsDscNative'
Node localhost {
AzDoServiceConnectionPermission AddServiceConnectionPermission {
Ensure = 'Present'
ProjectName = 'MyProject'
ConnectionName = 'MyAzureServiceConnection'
GroupName = '[MyProject]\Contributors'
isInherited = $true
Permissions = @(
@{
Identity = '[MyProject]\Contributors'
Permission = @{
'Use' = 'Allow'
}
}
)
}
}
}
Start-DscConfiguration -Path ./ExampleConfig -Wait -Verbose# Return the current configuration for AzDoServiceConnectionPermission
$properties = @{
ProjectName = 'MyProject'
ConnectionName = 'MyAzureServiceConnection'
GroupName = '[MyProject]\Contributors'
isInherited = $true
Permissions = @(
@{
Identity = '[MyProject]\Contributors'
Permission = @{
'Use' = 'Allow'
}
}
)
}
Invoke-DscResource -Name 'AzDoServiceConnectionPermission' -Method Get -Property $properties -ModuleName 'AzureDevOpsDscNative'parameters: {}
variables: {
ProjectName: MyProject,
ConnectionName: MyAzureServiceConnection
}
resources:
- name: Service Connection Contributors Permission
type: AzureDevOpsDscNative/AzDoServiceConnectionPermission
dependsOn:
- AzureDevOpsDscNative/AzDoServiceConnection/MyAzureServiceConnection
properties:
ProjectName: $ProjectName
ConnectionName: $ConnectionName
GroupName: '[$ProjectName]\Contributors'
isInherited: true
Permissions:
- Identity: '[$ProjectName]\Contributors'
Permission:
Use: Allow
Ensure: PresentLCM Initialization:
$params = @{
AzureDevopsOrganizationName = "SampleAzDoOrgName"
ConfigurationDirectory = "C:\Datum\DSCOutput\"
ConfigurationUrl = 'https://configuration-path'
JITToken = 'SampleJITToken'
Mode = 'Set'
AuthenticationType = 'ManagedIdentity'
ReportPath = 'C:\Datum\DSCOutput\Reports'
}
Invoke-DscPipelineRunner @params- Assert-BoundParameter
- Assert-ElevatedUser
- Assert-IPAddress
- Assert-Module
- AzDoAPI_0_ProjectCache
- AzDoAPI_1_GroupCache
- AzDoAPI_2_UserCache
- AzDoAPI_3_GroupMemberCache
- AzDoAPI_4_GitRepositoryCache
- AzDoAPI_5_PermissionsCache
- AzDoAPI_6_ServicePrinciple
- AzDoAPI_7_IdentitySubjectDescriptors
- AzDoAPI_8_ProjectProcessTemplates
- AzDoAPI_9_DevOpsClassificationNodes
- Compare-DscParameterState
- Compare-ResourcePropertyState
- ConvertFrom-DscResourceInstance
- ConvertTo-Base64String
- ConvertTo-CimInstance
- ConvertTo-HashTable
- Find-Certificate
- Format-Path
- Get-AzDevOpsOperation
- Get-AzDevOpsServicesApiUri
- Get-AzDevOpsServicesUri
- AzDoAgentPool
- AzDoAgentPoolPermission
- AzDoAgentQueue
- AzDoAreaNodes
- AzDoAreaPermission
- AzDoArtifactFeed
- AzDoArtifactFeedPermission
- AzDoArtifactFeedSettings
- AzDoArtifactFeedView
- AzDoAuditStream
- AzDoBranchPolicy
- AzDoCheckConfiguration
- AzDoDeploymentGroup
- AzDoEnvironmentApproval
- AzDoEnvironmentPermission
- AzDoExtension
- AzDoGitPermission
- AzDoGitRepository
- AzDoGroupMember
- AzDoGroupPermission
- AzDoIterationNodes
- AzDoIterationPermission
- AzDoNotificationSubscription
- AzDoOrganizationGroup
- AzDoOrganizationSettings
- AzDoPipeline
- AzDoPipelineEnvironment
- AzDoPipelinePermission
- AzDoPipelineSettings
- AzDoProcess
- AzDoProcessPermission
- AzDoProject
- AzDoProjectGroup
- AzDoProjectPermission
- AzDoProjectServices
- AzDoRepositorySettings
- AzDoSecurityNamespacePermission
- AzDoServiceConnection
- AzDoServiceConnectionPermission
- AzDoServiceHook
- AzDoTaskGroup
- AzDoTeam
- AzDoTeamMember
- AzDoTeamSettings
- AzDoUserEntitlement
- AzDoVariableGroup
- AzDoVariableGroupPermission
- AzDoWiki
- AzDoWIPTags