An authorisation standard allowing software to act for someone. In Azure Pipelines, choosing it for a GitHub service connection ties the connection to your own GitHub account; for integrations with Azure DevOps APIs, Microsoft Entra ID OAuth is the right choice.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains OAuth in context, with comparison tables and the common traps.
Terms in this definition
- Authorisation
Working out which actions and data a signed-in user or application is permitted, typically via role assignments. It comes after authentication.
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
- Azure Pipelines
CI/CD service within Azure DevOps that deploys applications and infrastructure as code, with environments, approvals and checks.
- Service connection
Lets Azure DevOps reach an outside service, for instance GitHub, a container registry or Azure Resource Manager. It is saved as a protected resource, so approvals, checks and permissions can apply to it.
- Connection
Resource that attaches a virtual network gateway to its peer, which may be an ExpressRoute circuit, a second VNet gateway (Vnet2Vnet) or a local network gateway over IPsec. Resetting it recovers a single tunnel and avoids rebooting the whole gateway.
- Azure DevOps
Microsoft's suite of DevOps services, among them Azure Boards and Azure Pipelines.
- Microsoft Entra ID OAuth
Microsoft's preferred route for applications calling Azure DevOps REST endpoints as a signed-in person. Its predecessor took no new registrations from April 2025 onwards and is being withdrawn in 2026.
Related terms
- App governance
Keeps watch over OAuth apps registered in Microsoft Entra ID, Google or Salesforce on behalf of Defender for Cloud Apps: it reports what permissions and data each app uses, and flags or limits those that look dangerous.
- Azure DevOps OAuth
Deprecated OAuth 2.0 platform native to Azure DevOps, used by apps calling its REST APIs. Registrations stopped in April 2025, removal is planned during 2026, and Entra ID OAuth replaces it for new integrations.
- Azure Files OAuth over REST
Capability allowing Microsoft Entra users, groups and managed identities to use OAuth tokens against the FileREST data API. The roles that grant it carry
readFileBackupSemanticsorwriteFileBackupSemantics; the SMB share roles don't apply. - Device code
OAuth grant for devices that lack a browser or keyboard: sign-in is completed on a separate device.
- Logic Apps authorization policy
Setting on a logic app that checks Microsoft Entra OAuth tokens sent to request-based triggers against an issuer and claims. SAS still works alongside it unless you also turn on Disable SAS authentication, which only Consumption offers.
- Logic Apps Consumption
Logic app type that runs multitenant, is billed per execution and holds one workflow per resource. It can use Entra OAuth authorisation policies on its Request trigger and supports disabling SAS.
- M2M
Lets automation call Azure Databricks by having a service principal swap its OAuth client ID and secret for short-lived access tokens, known as the client credentials flow; this machine-to-machine approach is the preferred one for unattended processes.
- OAuth app policy
Holds back OAuth apps in a GitHub organisation until an owner says yes. When it is on, approve Azure Boards, otherwise Azure DevOps may show no repositories at all.