Azure DevOps Audits

  • Thread starter Thread starter JustinMasse
  • Start date Start date
J

JustinMasse

Guest
We have a request from management who wants to have a list of connexions to AzureDevOps comming from outside the organization (this should be only possible by using Pesronal Access Tokens).

I'm using audtservice.dev.azure.com api's, I can get a lot of information including "authenticationMechanism" which is great. But somehow it seems like a lot of operations aren't captured in this audit. This should be showing actions made from/to "AutoRabit" but I can't see any logs comming from outside our network. I can't even see any entries made to the account used to grant security to this web tool.

Is there a way to increase the level of logs that are captured in this audit?

This is important since security has allowed the use of AzureDevOps in our organisation granted that Conditional Access Policy validation was operational and thus assuring that only complient devices can have access to business code. We need to be able to use PAT connexions but we would at least want to track the ones made from outside the organisation.

PS: Shouldn't there be a Azure DevOps / VSTS category in these forums?

Continue reading...
 
Back
Top