Azure DevOps

Azure DevOps Integration

Pensar Console integrates with Azure DevOps to scan and secure your repositories. The integration uses OAuth through your Microsoft (Entra) account — you authorize Pensar once, pick the Azure DevOps organization to link, and there are no personal access tokens to manage.

Prerequisites

Before connecting Azure DevOps, ensure you have:

  1. A Microsoft (Entra) account that has access to at least one Azure DevOps organization
  2. Permission to authorize applications for your Microsoft tenant (or an administrator who can grant consent — see Troubleshooting)

Connecting Azure DevOps

From Workspace Settings

  1. Navigate to SettingsIntegrationsSource control in your Pensar Console workspace
  2. Find the Azure DevOps row
  3. Click Connect
  4. You’ll be redirected to sign in with your Microsoft (Entra) account and authorize Pensar
  5. After authorizing, choose an Azure DevOps organization to link with this workspace
  6. You’ll be redirected back to Pensar Console with the organization connected

If your Microsoft account has access to multiple Azure DevOps organizations, Pensar lists them so you can pick the one to link. Each Pensar workspace links to a single Azure DevOps organization.

Adding Repositories

After linking an Azure DevOps organization, attach repositories directly to your workspace:

  1. Go to Attack SurfaceRepositories in Pensar Console
  2. Click Add repository
  3. Your Azure DevOps repositories appear in the picker — select one or more
  4. Click Attach & continue

Each repository you attach is connected to the workspace and recon / attack-surface analysis launches automatically — there is no separate project to create.

Managing the Integration

Viewing Connection Status

  1. Navigate to SettingsIntegrationsSource control
  2. Find the Azure DevOps row
  3. If connected, you’ll see the linked organization name, along with the option to unlink

Unlinking Azure DevOps

To remove the Azure DevOps integration:

  1. Navigate to SettingsIntegrationsSource control
  2. Find the Azure DevOps row
  3. Click Unlink and confirm

Unlinking Azure DevOps will prevent Pensar from scanning Azure DevOps repositories. Any repositories attached to your workspace from that organization will no longer be able to perform scans. You’ll need to reconnect to restore functionality.

Troubleshooting

Azure DevOps not provisioned in your tenant

If you see an error that Azure DevOps isn’t provisioned in your tenant, your Microsoft tenant has never used Azure DevOps and has no service principal for it. Sign in to dev.azure.com once with the same Microsoft account, then try connecting again.

If you see an “admin consent required” error, your tenant administrator must approve the Pensar application before you can connect. Ask an administrator to grant consent, then retry.

Account type not allowed

This means the Microsoft account you signed in with isn’t part of an organization that has access to Azure DevOps. Use an account that belongs to an organization with Azure DevOps access.

No Azure DevOps organizations

If Pensar reports that your account has no Azure DevOps organizations, your Microsoft account doesn’t have access to any. Ask an Azure DevOps administrator to add you to an organization, then try again.

Connection cancelled

If the connection was cancelled, you declined to grant Pensar access during the Microsoft sign-in. Start the Connect flow again and accept the requested permissions.

Need Help?

If you encounter issues setting up your Azure DevOps integration, please contact our support team at team@pensar.dev.