Restricting Access to Specific ADO Projects
This article details how to restrict access to specific ADO projects
Prerequisite: The Arnica application user should not be an organization-level admin, as Microsoft grants unconditional access to all ADO projects within an organization to org admins. As a best practice, create a dedicated application user for Arnica within the ADO organization and assign access only to the necessary ADO projects.
To restrict Arnica's integration user to specific ADO projects, follow these steps:
Login to ADO with a user that have Org-level Admin permissions
Click on the relevant ADO organization, and then "Organization settings"
Under "Security" click on "Permissions", then click on the "Users" tab
Locate the Arnica service account, click on it, and then click on the "Member of" tab
Click on the project you'd like to be excluded, and then click on “Project Settings” at the lower left side of the screen
Under “Project Settings" -> "General” -> “Permissions” -> “Users” -> Click on the Arnica Service Account, a list of permissions will be listed
Change all of the permissions to "Deny"
Additional Microsoft Documentation references:
Last updated
Was this helpful?