Azure DevOps Entra Migration

Overview

This article explains how Entra app authorization (using OAuth 2.0) affects the migration from legacy OAuth (using OAuth 1.0) and highlights the key considerations for connecting your projects. You will learn how to authorize the app, understand which settings are shared during migration, and avoid common issues involving personal Microsoft accounts, tenant consent, and project onboarding.

Signing Into the Developer Platform

The Developer Platform login page now displays two login options for Azure DevOps:

  • Legacy

  • Entra

Legacy Azure OAuth Sign-In

image-20260924-163224.png

Upon signing into the Developer Platform using the legacy Azure option, a banner at the top of the UI highlights the change and allows you to sign in using Entra instead:

image-20260924-164216.png

Note: Clicking the Sign in with Entra button will sign you out and back in using Entra. Being signed in with Entra is indicated at the top right corner of the UI.

image-20260924-164538.png

Important Notes

  • As of September 2026, projects can be onboarded using Legacy OAuth. In the future, this option will be blocked and force users to sign in using Entra to onboard new projects.

  • Projects already onboarded into Entra are greyed out and cannot be onboarded into Legacy OAuth.

    image-20260924-165200.png

Azure Entra Sign-In

image-20260924-162952.png

If some projects in your organization have not been migrated from Legacy OAuth to Azure Entra, this will be indicated in a banner, specifying the number of projects which fall under this category:

image-20260924-165425.png

At this stage, clicking either the Migrate Projects button within the banner or the Install more button at the top right will take you to the Onboard Projects menu.

The aforementioned Legacy OAuth projects which have not been migrated to Entra yet will be indicated by an exclamation mark on the right.

image-20260924-170253.png

Clicking the checkbox next to the project you wish to migrate will prompt you to confirm the migration. The migration is irreversible.

image-20260924-170658.png

The migration includes an Engine Settings step, allowing you to choose whether to import the existing engine settings (default) or alternatively set up new engine settings.

image-20260924-170950.png

General Notes about Migrating to Azure Entra

  1. Confirm that you are using a work or school account in the Microsoft Entra tenant. Personal Microsoft accounts are not supported for Entra authorization.

  2. Start the Entra app authorization flow from the product or integration setup page, then sign in to the appropriate Microsoft tenant.

  3. Review the requested permissions and approve the app installation if your account is allowed to provide consent.

  4. If consent is blocked, ask a tenant administrator to approve the app. After the administrator pre-authorizes the app, users in the tenant can install it according to the tenant's application-consent settings.

  5. Complete the project connection or migration, and review the resulting project and organization settings.

  6. If you use the Detect and Install New Projects setting, verify its behavior after authorization. The setting determines whether newly detected projects are onboarded through Entra or legacy OAuth based on whether the user already has any Entra-connected projects.

Limitations

  • Personal Microsoft accounts are not supported. Entra authorization supports organizational accounts in a Microsoft Entra tenant. This is a Microsoft platform restriction. See Microsoft's guidance on Entra OAuth migration for more information.

  • Tenant consent policies may prevent installation. By default, users may be able to install a publisher-verified app that does not request permissions requiring administrator consent. Tenant administrators can change these settings. If the tenant requires administrator approval, a tenant administrator must pre-authorize the app.

  • Permission requirements can vary by app. An app that requests a permission marked as requiring admin consent can be approved only by a tenant administrator. Check the permissions shown during installation before proceeding.

  • Organization settings are shared across authorization methods. If projects in the same organization use both legacy OAuth and Entra, organization-level settings apply to projects connected through both methods. Changes made to organization settings affect both integrations.

  • Project configuration migration should be verified. Most configuration is expected to migrate, but the exact result can depend on the configuration in use. After migration, review the project settings and confirm that the required configuration is present.

  • Detect and Install New Projects does not migrate existing legacy OAuth projects automatically. Enabling this setting does not convert existing legacy OAuth projects to Entra.

  • New-project onboarding depends on existing Entra connections. When the setting is enabled, a user who already has at least one Entra-connected project onboards newly detected projects through Entra. If the user has no Entra-connected projects, newly detected projects continue to onboard through legacy OAuth.