Loading...

Microsoft Entra: Action Required – Update Conditional Access Policies for Azure DevOps Sign-ins

Microsoft Entra: Action Required – Update Conditional Access Policies for Azure DevOps Sign-ins

Microsoft Entra requires updating Conditional Access policies by September 4, 2025, to explicitly include Azure DevOps (App ID: 499b84ac-1321-427f-aa17-267ca6975798) for secure sign-ins. Policies targeting the Windows Azure Service Management API will no longer protect Azure DevOps access. Microsoft Entra ID P1 or higher license is needed. Introduction Microsoft Entra is updating how Conditional Access (CA) policies apply to Azure DevOps sign-ins. Azure DevOps will no longer rely on the Azure Resource Manager (ARM) resource during sign-in or token refresh flows. This change ensures that access controls are applied directly to Azure DevOps. Organizations must update their Conditional Access policies to explicitly include Azure DevOps to maintain secure access. When this will happen This change will take effect starting September 2, 2025, and will be fully enforced by September 4, 2025, across all environments. How does this affect your organization? If your organization has Conditional Access policies targeting the Windows Azure Service Management API (App ID: 797f4846-ba00-4fd7-ba43-dac1f8f63013), those policies will no longer apply to Azure DevOps sign-ins. This may result in unprotected access unless these policies are updated to include Azure DevOps (App ID: 499b84ac-1321-427f-aa17-267ca6975798). Access controls such as MFA or compliant device requirements may not be enforced unless policies are updated. If you already have a policy that targets all users and all cloud apps and does not explicitly exclude Azure DevOps, no action is required—Azure DevOps sign-ins will continue to be protected. This change does not introduce any new user-facing experience or UI changes. Sign-in activity can be monitored using Microsoft Entra ID sign-in logs. Licensing requirement: Microsoft Entra ID P1 or P2 is required. There are no functional differences by license type. This is a feature change, not a new feature, so trial or preview options are not applicable. Unlicensed users may also be impacted. Existing Conditional Access policies will be affected, specifically those targeting the Windows Azure Service Management API. A small subset of tenants may see the app name as “Microsoft Visual Studio Team Services” instead of “Azure DevOps”—the App ID remains the same. Learn more:  What do you need to do to prepare? To ensure […]

The post Microsoft Entra: Action Required – Update Conditional Access Policies for Azure DevOps Sign-ins appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Entra: Action Required – Update Conditional Access Policies for Azure DevOps Sign-ins

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Purview: Auto-labeling scalability, policy management, and reporting enhancements

Microsoft Purview is improving auto-labeling capabilities to help organizations manage and validate labeling policies at enterprise scale. The...

19 hours ago

Updates available for Microsoft 365 Apps for all channels

We’ve released updates to the following update channels for Microsoft 365 Apps: Current Channel Monthly Enterprise Channel Semi-Annual E...

20 hours ago

Microsoft Purview | Data Lifecycle Management – Graph API Support for archive mailboxes

Microsoft is retiring Exchange Web Services (EWS) in Exchange Online by April 2027 and expanding Microsoft Graph API support for archive mailb...

20 hours ago

[Whiteboard] Legacy Whiteboard migration to OneDrive

Microsoft Whiteboard is migrating from legacy Azure-based storage to OneDrive-backed storage. Migration must be completed by September 25, 202...

20 hours ago

Microsoft Publisher: Reminder that support ends in October 2026

Microsoft Publisher support ends October 1, 2026; it will no longer be available in Microsoft 365 subscriptions. Users should convert or migra...

20 hours ago

[Whiteboard] Standalone app deprecation (Windows, Mobile)

Microsoft will retire standalone Whiteboard apps for Windows, iOS, and Android on October 16, 2026. Users must switch to accessing Whiteboard ...

20 hours ago

Microsoft Entra: Optimized passkey registration campaign experience

Microsoft Entra is enhancing passkey registration campaigns to optimize user experience and increase phishing-resistant authentication adoptio...

20 hours ago

The September 2026 Scan Cab is available

IMPORTANT: This notice only affects environments where Scan Cab is used to check for update compliance. What and why: The September 2026 Scan ...

20 hours ago

Teams admin center device state rules and health alerts retire; use Teams Rooms Pro Management portal

Teams admin center’s device state rules and health alerts will retire by late September 2026. Device health monitoring moves to the Team...

20 hours ago

Build apps in Microsoft Copilot Studio and Copilot Cowork

Microsoft announces a preview of app-building in Copilot Cowork starting September 8, 2026, with Copilot Studio following soon. Users with lic...

20 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.