EngineeringAzure DevOps

Azure DevOps

Connect Azure DevOps to RAD Security so RADBot and Automations can work with your repositories, work items, pull requests, and pipelines.

This guide walks you through creating an Azure DevOps personal access token (PAT), identifying your organization, and configuring the integration in RAD Security.

Azure DevOps provides Git repositories, work item tracking, and CI/CD pipelines. Once integrated, RADBot and Automations can read repositories, query and update work items, review and open pull requests, and inspect builds and pipelines — live, on demand.

This is an AI-first integration: it connects your Azure DevOps organization to RADBot and Automations over the official Azure DevOps MCP server. It does not continuously sync data into RAD Security — RADBot queries Azure DevOps directly when a question or automation requires it.

Prerequisites

Before you begin, ensure you have:

  • Access to an Azure DevOps organization (the {organization} in https://dev.azure.com/{organization})
  • Permission to create a personal access token for the account RAD Security will use
  • Access to a RAD Security workspace with integration permissions

Service Account Recommended: Create or use a dedicated Azure DevOps user for this integration rather than a personal account. Personal accounts may be removed when team members leave, which will break the integration. A PAT also inherits the permissions of the account that creates it, so a dedicated, least-privilege account keeps RADBot's access scoped.


Step 1: Choose the Account RAD Security Will Use

Use a dedicated user

Use (or create) a dedicated Azure DevOps user — for example a Microsoft Entra ID service account — and add it to your organization as a Member.

Grant project access

Add the user to the projects you want RADBot to work with, with the minimum access level required (for example, Basic with Contributor on the relevant repositories and work items). RADBot's reach is limited to the projects and repositories this account can see.

Azure DevOps permissions are project- and repository-scoped. Grant access only to the projects relevant to your security work.


Step 2: Create a Personal Access Token

Sign in as the service account

Sign in to https://dev.azure.com/{organization} as the account from Step 1.

Open Personal Access Tokens

  1. Click the User settings icon (top right, next to your avatar)
  2. Select Personal access tokens
  3. Click + New Token

Configure the token

  1. Name: a descriptive name, e.g. RAD Security
  2. Organization: select the organization you want to connect
  3. Expiration: set an expiration that matches your security policy (Azure DevOps PATs cannot be set to never expire on most organizations)

Select scopes

Grant the scopes that match the capabilities you want RADBot to have. For full read + write access, select:

ScopeAccessEnables
CodeRead & writeBrowse repos, files, and branches; read and create/update pull requests
Work ItemsRead & writeQuery work items; create, update, and comment on them
BuildReadList builds and pipelines
Project and TeamReadList projects (also used to verify the connection)

To give RADBot read-only access, select the Read variants of these scopes instead. The integration exposes write actions, but Azure DevOps will reject them if the PAT lacks write scopes — the PAT is your security boundary.

Create and copy the token

Click Create, then immediately copy the token.

Azure DevOps shows the token value only once. Copy it now — you cannot retrieve it later.


Step 3: Configure in RAD Security

In your RAD Security workspace, navigate to Data Sources → Integrations, select Azure DevOps, and enter:

ParameterDescriptionExample
OrganizationYour Azure DevOps organization name — the {organization} segment in https://dev.azure.com/{organization}contoso
Personal Access TokenThe PAT generated in Step 2xxxxxxxxxxxxxxxx...
Default Project (optional)A default project to scope operations to when one is not specifiedPlatform

The Organization is just the org name, not a full URL. The integration calls https://dev.azure.com/<organization>/_apis/projects to verify the organization and token.

Click Verify to test the credentials. When verification succeeds, save the integration.


Verify Integration

Open the integration

Navigate to Data Sources → Integrations → Engineering and locate your Azure DevOps integration.

Check the status

Confirm the connection status shows as Connected.

Try it in RADBot

Ask RADBot something that requires Azure DevOps, for example: "List the open pull requests in the Platform project."

Your Azure DevOps integration is now configured. RADBot and Automations can work with your repositories, work items, pull requests, and pipelines.


What RADBot Can Do

The exact actions available are the intersection of these capabilities and the scopes granted to your PAT.


Use Cases

Investigate with Live Context Let RADBot read repositories, pull requests, and work items while investigating an incident.

Automated Work Items Use Automations to create or update Azure DevOps work items from high-severity findings.

Code Search Search code across repositories for security anti-patterns, secrets, or vulnerable constructs.

Pipeline Visibility Ask RADBot about recent builds and pipeline status when triaging delivery risk.


Troubleshooting


Security Best Practices

Use a Service Account Never use a personal account. Use a dedicated Azure DevOps user so access survives staff changes and stays auditable.

Least Privilege Grant the smallest set of scopes and project access RADBot needs. Use read-only scopes if you do not want write actions.

Set Token Expiration Give the PAT an expiration that matches your security policy, and rotate it before it expires.

Audit Activity Periodically review work items and pull requests created by the service account to detect unexpected behavior.


Next Steps