Skip to content

Factories > Code forges

Connecting Azure DevOps to your factory

Open in ChatGPT ↗
Ask ChatGPT about this page
Open in Claude ↗
Ask Claude about this page
Copied!

Connect Azure DevOps Services to a factory with dedicated identities, repository access, and event-driven automations.

Connect Azure DevOps Services to a factory so agents can work in selected repositories, open pull requests, and start runs from work item and pull request events. Warp creates a dedicated Microsoft Entra identity for each factory’s Git and pull request operations.

The first-class integration supports hosted Azure DevOps Services at dev.azure.com. It doesn’t support Azure DevOps Server. To use a self-hosted Azure DevOps Server repository, configure it as another code forge. For standalone cloud agent environments, use the Azure DevOps access token setup.

Your personal Azure DevOps OAuth connection limits what appears during setup. The Azure DevOps Manager creates and manages each factory identity.

IdentityPurposeAccess
Your connected Azure DevOps accountLists resources during setup and supplies your identity for creator-based runs.Limited to resources your Azure DevOps user can read.
Azure DevOps ManagerCreates and maintains factory identities in one Microsoft Entra tenant and Azure DevOps organization.Has Basic access and belongs to Project Collection Administrators.
Factory identityAuthenticates the factory’s Git and pull request operations after a run starts.Has Basic access and permissions on the selected repositories.

Each factory identity consists of a separate Microsoft Entra application and service principal that Warp adds to Azure DevOps.

  • A Warp team with Warp Factories access - A factory belongs to a Warp team.
  • An Azure DevOps Services organization - Use an organization hosted at dev.azure.com, with the project and repositories the factory needs.
  • A connected Azure DevOps user - Connect a user who can read the organization, project, and repositories you want to select.
  • An active connection for each automation creator - The user who creates an Azure DevOps automation must keep their own Azure DevOps OAuth connection active with the required scopes.
  • Microsoft Entra and Azure DevOps administrators - Administrators with the roles listed below approve and add the Manager.

The Microsoft Entra and Azure DevOps approvals can be completed by different people. A setup link lets each administrator complete their step without a Warp account.

SystemAdministratorWhat the administrator approves
Microsoft EntraGlobal Administrator or Privileged Role AdministratorThe Manager’s Microsoft Graph Application.ReadWrite.OwnedBy permission, limited to applications the Manager owns.
Azure DevOpsProject Collection AdministratorBasic access and Project Collection Administrators membership. Warp doesn’t retain the administrator’s sign-in.

Reuse tenant approval for another Azure DevOps organization in the same Microsoft Entra tenant. Each organization requires Azure DevOps approval.

Start from factory setup to connect your account, select repositories, and provision the runtime identity.

  1. Sign in to the Warp Factories web app. Next to the factory list, click + to create a factory.
  2. In the code host step, find the Azure DevOps row and click Connect. Complete the Microsoft sign-in to connect your Azure DevOps user.
  3. Choose an Azure DevOps organization and project, then select the repositories the factory will use. Only resources your connected user can read appear.
  4. If the organization already has an active Azure DevOps Manager, continue setup. Otherwise, connect the Manager yourself or send the setup link to the required administrators.
  5. Complete the Manager approval in this order:
    1. A Global Administrator or Privileged Role Administrator completes the Microsoft Entra approval.
    2. A Project Collection Administrator completes the Azure DevOps approval.
  6. Continue factory setup. Warp creates the factory identity, adds Azure DevOps Basic access, and grants access to the selected repositories. Microsoft and Azure DevOps can take several minutes to apply these changes.

When setup confirms that the identity is ready, the factory uses that identity for Git and pull request operations. You can retry identity provisioning from the factory’s settings if setup is interrupted.

An Azure DevOps automation starts a factory run when a supported event matches its filters. Before starting a run, Warp checks the automation creator’s Azure DevOps connection. New Azure DevOps factories include a default automation for pull request mentions, work item mentions, and work item assignments.

To configure an automation as code, ask the Warp Agent to update the factory definition or edit its automations/ files directly. See definitions as code.

To add or change a trigger in the factory dashboard:

  1. In the factory dashboard, open Automations, then create an automation or edit an existing one.
  2. Add an Azure DevOps trigger, then choose an event and its filters.
  3. Click Save. Perform a matching action in Azure DevOps and confirm that a run starts in the factory dashboard.

For general filter behavior, see factory automations.

Azure DevOps eventAvailable filters
Work item createdWork item types, labels, assignees, and authors
Work item assignedWork item types, labels, assignees, and authors
Work item labeledWork item types, labels, assignees, and authors
Mentioned in a work itemMentioned users
Pull request createdRepository and target branches
Pull request mergedRepository and target branches
Pull request closedRepository and target branches
Pull request updatedRepository and target branches
Pull request commentedRepository and target branches
Mentioned in a pull requestRepository and mentioned users

Factory definition files also accept the Azure DevOps push event with repository and branch filters. The automation editor doesn’t currently offer this event.

Definition files accept source_repos for pull request events. Use it to match the repository that contains the pull request’s source branch. See triggers in a factory definition for the complete schema.

An organization, project, or repository doesn’t appear

Section titled “An organization, project, or repository doesn’t appear”

Cause: Your Azure DevOps user lacks access to the resource.

Solution: Grant the user access, then refresh the connection.

Cause: The Microsoft Entra approval is incomplete.

Solution: Complete the Microsoft Entra step before the Azure DevOps step. Reopen the setup link if another administrator completed the first step.

Cause: Microsoft Entra and Azure DevOps permission changes can take several minutes to propagate.

Solution: Wait, then retry from the factory’s settings if setup reports an error.

Cause: The automation is disabled, a filter doesn’t match, or its creator’s Azure DevOps OAuth connection is missing, revoked, or under-scoped.

Solution: Enable the automation, check every filter, and reconnect its creator’s Azure DevOps account with the required scopes.

Factory identity doesn’t appear in comment mention autocomplete

Section titled “Factory identity doesn’t appear in comment mention autocomplete”

Cause: Azure DevOps doesn’t yet recognize the factory identity for comment autocomplete.

Workaround: Make Azure DevOps recognize the factory identity by using it once in the organization:

  1. In the Azure DevOps organization and project connected to the factory, assign the factory identity to a work item and save the work item.
  2. Return to the comment, enter @ followed by the factory identity’s name, then select the identity from autocomplete.
  3. Confirm that Azure DevOps formats the selection as a mention. Plain text with the same name doesn’t trigger the automation.

The identity value 'X' for field 'Assigned To' is an unknown identity.

Section titled “The identity value 'X' for field 'Assigned To' is an unknown identity.”

Cause: Azure DevOps can’t resolve the factory identity for the current work item. This can happen when the work item is outside the organization or project configured for the factory.

Solution:

  1. In the factory’s settings, confirm its Azure DevOps organization and project.
  2. In Azure DevOps, open the work item from that organization and project, then assign the factory identity again.