Cannot access Azure DevOps permissions report api without a "Full Access" PAT

Viewed 70

I'm trying to call the apis/permissionsreport GET endpoint. As per the responses to

Cannot request permissions report through API

I'm utilizing a project collection administrator account. However, the AD level admins restricted the ability of everyone to create full access PATs. I tried to create a PAT token with all available scopes checked, but that was not sufficient to be able to call the endpoint successfully. I validated that on personal ADO instance I can create full access tokens on- a full access token worked in postman, an access token with all scopes selected did not. I get a 401 error with no message body in response.

Is there any way to call this API without a full access PAT token? Perhaps OAUTH?

2 Answers

You can try to set the scope to Custom defined , try to only select Read access or Read&Execute access in the Build Scope, the PAT should be work fine as the following pictures set:

Custom defined

But yet not all paths are mapped to required scopes. A number of the public APIs are currently unassociated with a PAT scope, and can therefore only be used with a full scoped PAT.

So we recommend you to use OAuth to Authorize access to REST APIs.

For more information, you can refer to Authorize access to REST APIs with OAuth 2.0.

In my case adding the Security (Read, write, and manage) -> Manage scope to my PAT was the solution

Related