This article explains how to update the read/write permissions for your Azure DevOps integration in Vanta.
⚠️ Note: Changing your access level requires re-authenticating via Microsoft Entra ID. You will need an account with admin consent permissions in your Entra tenant to complete this process. Relinking will NOT cause data loss.
Contact your IT or Entra administrator if you are unsure.
Before you begin
Confirm you are an organization owner in Azure DevOps. An easy way to verify this is to navigate to your Azure DevOps organization page and confirm that Organization Settings is visible in the sidebar. If it is not, you may not have the required access.
Instructions
In Vanta, go to the Integrations page and search for Azure DevOps.
Select Manage, then Edit.
Click the pencil icon next to the connection you want to update permissions for.
You will see the current access level selected:
Enable read access only: Vanta can monitor repositories, users, and work items
Enable read and write access: additionally allows Vanta to create work items in Azure DevOps from within the platform
Select the access level you want and proceed to the next step.
(Optional) If your organization uses a specific Microsoft Entra ID tenant, check Use specific tenant ID and enter your Tenant ID.
💡Tip: To find your Tenant ID: in the Azure Portal, go to Microsoft Entra ID > Overview.
Now click Connect Azure DevOps, which will bring you to Microsoft Azure. If you are not signed in already, you will be prompted to sign in with your Microsoft Account, and then the page will redirect you back to Vanta. If you are signed in already in another tab, you will be redirected back to Vanta and presented with a menu like below:
From here, you can select your organization and finish linking by choosing the organization you want Vanta monitoring from the drop-down menu. Once you've completed this, click Link Azure DevOps account.
ℹ️ Note: To connect successfully, you must have access to all repositories in the selected organization.
