Automation Platform > Integrations
Connecting Azure DevOps to a factory
# Connecting Azure DevOps to a factory Connect Azure DevOps Services to a factory so agents can work in selected repositories, open pull requests, and start runs from work item and pull request events. Warp creates a dedicated identity for each factory's Git and pull request operations. Automation dispatch separately requires the automation creator's active Azure DevOps connection. {/* VERIFY: Confirm first-class Azure DevOps Services support is enabled in production before merging this documentation. */} :::note Warp Factories is in Early Access and available to a limited set of teams. [Request access](https://www.warp.dev/factories/request-access) to use it with your team. ::: The first-class integration supports hosted Azure DevOps Services at `dev.azure.com`. It doesn't support Azure DevOps Server. To use a self-hosted Azure DevOps Server repository, [configure it as another code forge](/factories/code-forges/other-code-forges/) with your own credentials and setup commands. ## What the Azure DevOps integration does * **Repository access** - Select repositories from one Azure DevOps organization and project for the factory. * **Dedicated runtime identity** - Give each factory its own Microsoft Entra application and service principal for Git and pull request operations. * **Trigger** - Start factory runs from supported Azure DevOps work item and pull request events. * **Scoped administration** - Approve one Warp-managed Azure DevOps Manager for an organization, then use it to provision identities for multiple factories. ## How identities and access work The integration separates setup access from runtime access. The Manager is a Warp-managed, multitenant Microsoft Entra application. Approval creates its service principal in your tenant and adds it to the Azure DevOps organization. | Identity | Purpose | Access | | --- | --- | --- | | Your connected Azure DevOps account | Lists the organizations, projects, and repositories you can choose during setup. If you create an Azure DevOps automation, Warp also binds your connection when an event dispatches a run. | Limited to resources your Azure DevOps user can read. An automation requires its creator's active, correctly scoped connection; another user's connection can't replace it. | | Azure DevOps Manager | Creates and maintains factory identities in one Microsoft Entra tenant and Azure DevOps organization. | Owns only the Entra applications it creates. In Azure DevOps, it has Basic access and belongs to Project Collection Administrators. | | Factory identity | Authenticates the factory's Git and pull request operations after a run starts. | Has Basic access, project visibility, Service Hooks access, work item access, and permissions on the selected repositories. | Each factory identity consists of a separate Microsoft Entra application and service principal that Warp adds to Azure DevOps. Warp configures workload identity federation, so the factory doesn't need a stored client secret. ## Requirements * **A Warp team with Warp Factories access** - A factory belongs to a [Warp team](/knowledge-and-collaboration/teams/). * **An Azure DevOps Services organization** - Use an organization hosted at `dev.azure.com`, with the project and repositories the factory needs. * **A connected Azure DevOps user** - Connect a user who can read the organization, project, and repositories you want to select. * **An active connection for each automation creator** - The Warp user who creates an Azure DevOps automation must keep their own Azure DevOps OAuth connection active and correctly scoped. Another user's connection can't be substituted when an event dispatches the automation. * **A Microsoft Entra administrator** - A Global Administrator or Privileged Role Administrator approves the Azure DevOps Manager. * **An Azure DevOps administrator** - A Project Collection Administrator adds the Manager to the organization. The Microsoft Entra and Azure DevOps approvals can be completed by different people. A setup link lets each administrator complete their step without a Warp account. ### Required administrator permissions | System | Administrator | What the administrator approves | | --- | --- | --- | | Microsoft Entra | Global Administrator or Privileged Role Administrator | The Azure DevOps Manager and its Microsoft Graph `Application.ReadWrite.OwnedBy` permission. This permission lets the Manager create applications and manage only applications it owns. | | Azure DevOps | Project Collection Administrator | Basic access for the Manager and membership in the organization's Project Collection Administrators group. Warp uses the administrator's sign-in for this approval and doesn't retain it. | Tenant approval can be reused when you connect another Azure DevOps organization in the same Microsoft Entra tenant. Azure DevOps approval is required for each organization. :::caution The Manager and each factory identity can each consume one Azure DevOps Basic seat. Check available licenses before connecting an organization or adding factories. ::: ## Connect Azure DevOps Start from factory setup to connect your account, select repositories, and provision the runtime identity. 1. Sign in to the <a href=https://platform.warp.dev>Warp Factories web app</a>. Next to the factory list, click **+** to create a factory. 2. In the code host step, find the Azure DevOps row and click **Connect**. Complete the Microsoft sign-in to connect your Azure DevOps user. 3. Choose an Azure DevOps organization and project, then select the repositories the factory will use. Only resources your connected user can read appear. 4. If the organization already has an active Azure DevOps Manager, continue setup. Otherwise, connect the Manager yourself or send the setup link to the required administrators. 5. Complete the Manager approval in this order: 1. A Global Administrator or Privileged Role Administrator completes the Microsoft Entra approval. 2. A Project Collection Administrator completes the Azure DevOps approval. 6. Continue factory setup. Warp creates the factory identity, adds Azure DevOps Basic access, and grants access to the selected repositories. Microsoft and Azure DevOps can take several minutes to apply these changes. When setup confirms that the identity is ready, the factory uses that identity for Git and pull request operations. You can retry identity provisioning from the factory's settings if setup is interrupted. Azure DevOps automations still require the automation creator's personal connection. Workspace admins can also manage organization-level Managers in the Azure DevOps Managers section of the Admin Panel. Any active workspace member can complete or delegate Manager setup while creating a factory. ## Configure Azure DevOps automations An Azure DevOps automation starts a factory run when a supported event matches its filters. Before creating the run, Warp verifies and binds the automation creator's active Azure DevOps OAuth connection. A missing, revoked, under-scoped, or differently owned connection stops dispatch. New Azure DevOps factories include a default automation for pull request mentions, work item mentions, and work item assignments. To add or change a trigger: 1. In the factory dashboard, open **Automations**, then create an automation or edit an existing one. 2. Add an Azure DevOps trigger, then choose an event and its filters. 3. Click **Save**. Perform a matching action in Azure DevOps and confirm that a work item starts in the factory dashboard. For general filter behavior, see [factory automations](/factories/automations/). ### Supported events and filters | Azure DevOps event | Available filters | | --- | --- | | Work item created | Work item types, labels, assignees, and authors | | Work item assigned | Work item types, labels, assignees, and authors | | Work item labeled | Work item types, labels, assignees, and authors | | Mentioned in a work item | Mentioned users | | Pull request created | Repository and target branches | | Pull request merged | Repository and target branches | | Pull request closed | Repository and target branches | | Pull request updated | Repository and target branches | | Pull request commented | Repository and target branches | | Mentioned in a pull request | Repository and mentioned users | Azure DevOps push events aren't currently available as automation triggers. ## Troubleshooting * **An organization, project, or repository doesn't appear** - Confirm that your connected Azure DevOps user can read it, then refresh the connection. * **Manager approval can't continue** - Complete the Microsoft Entra step before the Azure DevOps step. If another administrator completed the first step, reopen the setup link. * **Identity provisioning remains in progress** - Microsoft Entra and Azure DevOps permission changes can take several minutes to propagate. Retry from the factory's settings if the setup reports an error. * **An event doesn't start a run** - Confirm the automation is enabled and that every configured filter matches the Azure DevOps event. The user who created the automation must also have an active Azure DevOps OAuth connection with the required scopes; another user's connection can't replace it. ### Factory identity doesn't appear in comment mention autocomplete **Cause:** The Azure DevOps identity picker for work item comments filters service-principal identities from its normal search results. This is an Azure DevOps platform limitation that Warp can't change. Warp can detect the factory identity after Azure DevOps saves the comment with the identity's mention metadata. **Solution:** Add the factory identity to Azure DevOps's recently used identity cache: 1. In the Azure DevOps organization and project connected to the factory, assign the factory identity to a work item and save the work item. 2. Return to the comment and enter `@` followed by the factory identity's name. The identity may now appear in autocomplete. If you enter the name without autocomplete, confirm that Azure DevOps formats it as a mention instead of plain text. ### `The identity value 'X' for field 'Assigned To' is an unknown identity.` **Cause:** Azure DevOps can't resolve the factory identity for the current work item. This can happen when the work item is outside the organization or project configured for the factory. **Solution:** 1. In the factory's settings, confirm its Azure DevOps organization and project. 2. In Azure DevOps, open the work item from that organization and project, then assign the factory identity again. ## Related pages * [Warp Factories quickstart](/factories/quickstart/) - Create a factory and send its first work item. * [Factory automations](/factories/automations/) - Configure triggers, filters, and routing. * [Other code forges](/factories/code-forges/other-code-forges/) - Connect repositories that don't have a first-class integration, including Azure DevOps Server. * [Infrastructure and security](/factories/infrastructure-and-security/) - Review how factories handle execution, credentials, and access.Tell me about this feature: https://docs.warp.dev/platform/integrations/azure-devops/Connect Azure DevOps Services to a factory with dedicated identities, repository access, and event-driven automations.
Connect Azure DevOps Services to a factory so agents can work in selected repositories, open pull requests, and start runs from work item and pull request events. Warp creates a dedicated identity for each factory’s Git and pull request operations. Automation dispatch separately requires the automation creator’s active Azure DevOps connection.
The first-class integration supports hosted Azure DevOps Services at dev.azure.com. It doesn’t support Azure DevOps Server. To use a self-hosted Azure DevOps Server repository, configure it as another code forge with your own credentials and setup commands.
What the Azure DevOps integration does
Section titled “What the Azure DevOps integration does”- Repository access - Select repositories from one Azure DevOps organization and project for the factory.
- Dedicated runtime identity - Give each factory its own Microsoft Entra application and service principal for Git and pull request operations.
- Trigger - Start factory runs from supported Azure DevOps work item and pull request events.
- Scoped administration - Approve one Warp-managed Azure DevOps Manager for an organization, then use it to provision identities for multiple factories.
How identities and access work
Section titled “How identities and access work”The integration separates setup access from runtime access. The Manager is a Warp-managed, multitenant Microsoft Entra application. Approval creates its service principal in your tenant and adds it to the Azure DevOps organization.
| Identity | Purpose | Access |
|---|---|---|
| Your connected Azure DevOps account | Lists the organizations, projects, and repositories you can choose during setup. If you create an Azure DevOps automation, Warp also binds your connection when an event dispatches a run. | Limited to resources your Azure DevOps user can read. An automation requires its creator’s active, correctly scoped connection; another user’s connection can’t replace it. |
| Azure DevOps Manager | Creates and maintains factory identities in one Microsoft Entra tenant and Azure DevOps organization. | Owns only the Entra applications it creates. In Azure DevOps, it has Basic access and belongs to Project Collection Administrators. |
| Factory identity | Authenticates the factory’s Git and pull request operations after a run starts. | Has Basic access, project visibility, Service Hooks access, work item access, and permissions on the selected repositories. |
Each factory identity consists of a separate Microsoft Entra application and service principal that Warp adds to Azure DevOps. Warp configures workload identity federation, so the factory doesn’t need a stored client secret.
Requirements
Section titled “Requirements”- A Warp team with Warp Factories access - A factory belongs to a Warp team.
- An Azure DevOps Services organization - Use an organization hosted at
dev.azure.com, with the project and repositories the factory needs. - A connected Azure DevOps user - Connect a user who can read the organization, project, and repositories you want to select.
- An active connection for each automation creator - The Warp user who creates an Azure DevOps automation must keep their own Azure DevOps OAuth connection active and correctly scoped. Another user’s connection can’t be substituted when an event dispatches the automation.
- A Microsoft Entra administrator - A Global Administrator or Privileged Role Administrator approves the Azure DevOps Manager.
- An Azure DevOps administrator - A Project Collection Administrator adds the Manager to the organization.
The Microsoft Entra and Azure DevOps approvals can be completed by different people. A setup link lets each administrator complete their step without a Warp account.
Required administrator permissions
Section titled “Required administrator permissions”| System | Administrator | What the administrator approves |
|---|---|---|
| Microsoft Entra | Global Administrator or Privileged Role Administrator | The Azure DevOps Manager and its Microsoft Graph Application.ReadWrite.OwnedBy permission. This permission lets the Manager create applications and manage only applications it owns. |
| Azure DevOps | Project Collection Administrator | Basic access for the Manager and membership in the organization’s Project Collection Administrators group. Warp uses the administrator’s sign-in for this approval and doesn’t retain it. |
Tenant approval can be reused when you connect another Azure DevOps organization in the same Microsoft Entra tenant. Azure DevOps approval is required for each organization.
Connect Azure DevOps
Section titled “Connect Azure DevOps”Start from factory setup to connect your account, select repositories, and provision the runtime identity.
- Sign in to the Warp Factories web app. Next to the factory list, click + to create a factory.
- In the code host step, find the Azure DevOps row and click Connect. Complete the Microsoft sign-in to connect your Azure DevOps user.
- Choose an Azure DevOps organization and project, then select the repositories the factory will use. Only resources your connected user can read appear.
- If the organization already has an active Azure DevOps Manager, continue setup. Otherwise, connect the Manager yourself or send the setup link to the required administrators.
- Complete the Manager approval in this order:
- A Global Administrator or Privileged Role Administrator completes the Microsoft Entra approval.
- A Project Collection Administrator completes the Azure DevOps approval.
- Continue factory setup. Warp creates the factory identity, adds Azure DevOps Basic access, and grants access to the selected repositories. Microsoft and Azure DevOps can take several minutes to apply these changes.
When setup confirms that the identity is ready, the factory uses that identity for Git and pull request operations. You can retry identity provisioning from the factory’s settings if setup is interrupted. Azure DevOps automations still require the automation creator’s personal connection.
Workspace admins can also manage organization-level Managers in the Azure DevOps Managers section of the Admin Panel. Any active workspace member can complete or delegate Manager setup while creating a factory.
Configure Azure DevOps automations
Section titled “Configure Azure DevOps automations”An Azure DevOps automation starts a factory run when a supported event matches its filters. Before creating the run, Warp verifies and binds the automation creator’s active Azure DevOps OAuth connection. A missing, revoked, under-scoped, or differently owned connection stops dispatch. New Azure DevOps factories include a default automation for pull request mentions, work item mentions, and work item assignments.
To add or change a trigger:
- In the factory dashboard, open Automations, then create an automation or edit an existing one.
- Add an Azure DevOps trigger, then choose an event and its filters.
- Click Save. Perform a matching action in Azure DevOps and confirm that a work item starts in the factory dashboard.
For general filter behavior, see factory automations.
Supported events and filters
Section titled “Supported events and filters”| Azure DevOps event | Available filters |
|---|---|
| Work item created | Work item types, labels, assignees, and authors |
| Work item assigned | Work item types, labels, assignees, and authors |
| Work item labeled | Work item types, labels, assignees, and authors |
| Mentioned in a work item | Mentioned users |
| Pull request created | Repository and target branches |
| Pull request merged | Repository and target branches |
| Pull request closed | Repository and target branches |
| Pull request updated | Repository and target branches |
| Pull request commented | Repository and target branches |
| Mentioned in a pull request | Repository and mentioned users |
Azure DevOps push events aren’t currently available as automation triggers.
Troubleshooting
Section titled “Troubleshooting”- An organization, project, or repository doesn’t appear - Confirm that your connected Azure DevOps user can read it, then refresh the connection.
- Manager approval can’t continue - Complete the Microsoft Entra step before the Azure DevOps step. If another administrator completed the first step, reopen the setup link.
- Identity provisioning remains in progress - Microsoft Entra and Azure DevOps permission changes can take several minutes to propagate. Retry from the factory’s settings if the setup reports an error.
- An event doesn’t start a run - Confirm the automation is enabled and that every configured filter matches the Azure DevOps event. The user who created the automation must also have an active Azure DevOps OAuth connection with the required scopes; another user’s connection can’t replace it.
Factory identity doesn’t appear in comment mention autocomplete
Section titled “Factory identity doesn’t appear in comment mention autocomplete”Cause: The Azure DevOps identity picker for work item comments filters service-principal identities from its normal search results. This is an Azure DevOps platform limitation that Warp can’t change. Warp can detect the factory identity after Azure DevOps saves the comment with the identity’s mention metadata.
Solution: Add the factory identity to Azure DevOps’s recently used identity cache:
- In the Azure DevOps organization and project connected to the factory, assign the factory identity to a work item and save the work item.
- Return to the comment and enter
@followed by the factory identity’s name. The identity may now appear in autocomplete. If you enter the name without autocomplete, confirm that Azure DevOps formats it as a mention instead of plain text.
The identity value 'X' for field 'Assigned To' is an unknown identity.
Section titled “The identity value 'X' for field 'Assigned To' is an unknown identity.”Cause: Azure DevOps can’t resolve the factory identity for the current work item. This can happen when the work item is outside the organization or project configured for the factory.
Solution:
- In the factory’s settings, confirm its Azure DevOps organization and project.
- In Azure DevOps, open the work item from that organization and project, then assign the factory identity again.
Related pages
Section titled “Related pages”- Warp Factories quickstart - Create a factory and send its first work item.
- Factory automations - Configure triggers, filters, and routing.
- Other code forges - Connect repositories that don’t have a first-class integration, including Azure DevOps Server.
- Infrastructure and security - Review how factories handle execution, credentials, and access.