---
sourceDocument: Australia IT Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/it-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Onboard Azure DevOps using Service Catalog

# Onboard Azure DevOps to DevOps Change Velocity --- Service Catalog {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read  
Create, connect, discover, and configure your Azure DevOps instance using the ServiceNow
Service Catalog.

## Before you begin

Role required: sn_devops.admin or sn_devops.tool_owner

## Procedure

1. Navigate to AllService CatalogCatalog DefinitionsMaintain Items and search for DevOps.  
   Note:  
   You can also access the service catalog from Employee Center or Service portal.
2. From the DevOps catalog items, select and activate DevOps App Onboarding and DevOps Tool Onboarding.
3. After activating, select DevOps Tool Onboarding and select Try it.
4. In the DevOps Tool Onboarding form, enter the tool details:  
   {#onboard-azure-devops-service-catalog__table_ubw_p1p_gwb__entry__2}

   | Field | Description |
   |-|-|
   | Tool name | Name for your Azure DevOps integration. |
   | Tool integration | Select Azure DevOps. |
   | Connect to an organization or project | Select from the list. * Connect an organization: Connect directly at your Azure DevOps organization level. All the projects within the organization will be discovered, and you can choose to configure multiple projects within the organization. * Connect a project: Connect directly at the project level. {#onboard-azure-devops-service-catalog__ul_esh_sx2_xwb} |
   | Tool URL | Azure DevOps organization URL (for example, <kbd class="ph userinput">https://dev.azure.com/&lt;your organization&gt;</kbd>) or the Azure DevOps project URL (for example, <kbd class="ph userinput">https://dev.azure.com/&lt;your organization&gt;/&lt;your project&gt;</kbd>). |
   | Credential type | Type of credential, Basic Auth or OAuth 2.0. Basic Auth 1. Enter your ADO instance username. 2. Enter the [Personal access token (PAT)](https://docs.microsoft.com/en-us/azure/devops/organizations/accounts/use-personal-access-tokens-to-authenticate?view=azure-devops&tabs=preview-page) or password for your Azure DevOps instance. Note: When you generate a Personal access token (PAT) for Azure DevOps, you must select the scopes to authorize if you aren't granting complete access. See [Azure DevOps PAT scopes for DevOps](https://servicenow-prod.fluidtopics.net/Nc6M2ycUN~yl1v0s760bGw "Scope access levels are required when using a personal access token (PAT) to access Azure DevOps during setup."). {#onboard-azure-devops-service-catalog__ol_kts_jgz_5cc} OAuth 2.0 Pre-requisites: * [Create a tenant in Microsoft Entra](https://servicenow-prod.fluidtopics.net/eXmk6AoNbg15x2jr~f3Gxg#create-a-new-tenant-in-microsoft-entra-id "Create a tenant in Microsoft Entra and set up the required permissions to create an Azure DevOps (ADO) app.") * [Add a user to tenant in Microsoft Entra](https://servicenow-prod.fluidtopics.net/eXmk6AoNbg15x2jr~f3Gxg#add-a-user-to-tenant "Add a user who contains the admin role, to the tenant created in the previous procedure.") * [Create an organization in Azure portal](https://servicenow-prod.fluidtopics.net/eXmk6AoNbg15x2jr~f3Gxg#create-an-org-in-the-tenant "Create an organization in the new tenant, which has access to create an app.") * [Create an Azure DevOps app](https://servicenow-prod.fluidtopics.net/eXmk6AoNbg15x2jr~f3Gxg#register-an-ado-app "Create and configure an Azure DevOps (ADO) app and copy the required values to enable OAuth 2.0 authentication with your ServiceNow instance.") * [Register Azure DevOps as an OAuth provider](https://servicenow-prod.fluidtopics.net/eXmk6AoNbg15x2jr~f3Gxg#create-application-registry "Use the information generated during Azure DevOps (ADO) app account configuration to register Azure DevOps as an OAuth provider and enable the instance to request OAuth 2.0 tokens.") * [Configure organization and project level settings](https://servicenow-prod.fluidtopics.net/eXmk6AoNbg15x2jr~f3Gxg#add-the-app-to-your-organization "Configure organization and project level settings for your app.") * [Create credential record and get OAuth token](https://servicenow-prod.fluidtopics.net/eXmk6AoNbg15x2jr~f3Gxg#create-credential-record-and-get-oauth-token "Create credential record and get OAuth token.") {#onboard-azure-devops-service-catalog__ul_nwp_ccf_vcc} In the Tool credential field, select an OAuth 2.0 tool credential record. Note: Only records that are not in use and configured for ADO can be selected as an existing credential record. |
   | Do you wish to configure webhook for this tool? | Option to enable configuring webhooks automatically for Azure DevOps. Select to enable. Note: This option isn't available if you're connecting at the organization level. You can configure webhooks from the tool records page. |
   | Integration username | This field is available only when the option to configure webhook is selected. Enter the username for the DevOps Integration User account. Note: * The step to enter the integration user name and password is required to configure only when DevOps Config is installed or the This property decides whether to create a Generic Connection on configure operation for Azure DevOps property is enabled. If this step is not required, webhooks are configured using token-based authentication. * When DevOps Config is installed or the Generic Connection on configure operation for Azure DevOps property is enabled, you can regenerate token (auto-configure with new token) from the workspace UI only, which will update integration user password. When DevOps Config is not installed, token can be regenerated from both the workspace and classic UI for token based authentication. Re-generate your token periodically for better security. {#onboard-azure-devops-service-catalog__ul_yq4_1l5_1yb}. |
   | Integration user password | This field is available only when the option to configure webhook is selected. Enter the password for the DevOps Integration User account. Note: * The step to enter the integration user name and password is required to configure only when DevOps Config is installed or the This property decides whether to create a Generic Connection on configure operation for Azure DevOps property is enabled. If this step is not required, webhooks are configured using token-based authentication. * When DevOps Config is installed or the Generic Connection on configure operation for Azure DevOps property is enabled, you can regenerate token (auto-configure with new token) from the workspace UI only, which will update integration user password. When DevOps Config is not installed, token can be regenerated from both the workspace and classic UI for token based authentication. Re-generate your token periodically for better security. {#onboard-azure-devops-service-catalog__ul_f21_yn5_1yb} |
   | Use MID Server | Optional. Select  MID Server for an on-premises tool that is attached to a  MID Server. Application is automatically set to  DevOps and capability is set to REST. |
   [ ]

   {#onboard-azure-devops-service-catalog__table_ubw_p1p_gwb}

   For a list of all the permissions required on the credentials for connecting to Azure DevOps, see Azure DevOps permissions in [Permissions required for DevOps tools](https://servicenow-prod.fluidtopics.net/rkQZOOxQSNdDZ7d5eHch0A "Permissions required in your third-party tool to connect to DevOps Change Velocity.").
5. Select Order Now.  
   A request is created. When the request is approved:
   * If connecting to an organization, the tool is created.
   * If connecting to a project, the tool is created, connected, and project objects like plans, repositories, and pipelines are discovered.
   {#onboard-azure-devops-service-catalog__ul_r2k_ls4_ywb}

When connecting to a project, for the discovered objects, you can import historical data from the tool and also associate an application with it.

6. From the DevOps catalog items, select DevOps App Onboarding.
7. Select Try It.
8. In the DevOps App Onboarding form, enter the details:  

   |-|-|
   | Are you creating a new app or adding to an existing one? | Select from the options whether to create a new app or use an existing app. |
   | App | Enter the name for the app that you're creating or using. |
   | Onboarding pipelines | Enter the connected Azure DevOps tool name. |
   | Pipelines | Select the pipelines for which you want to import historical data. |
   | Artifact repositories | Select the artifacts for which you want to import historical data. |
   | Onboarding repositories | Enter the connected Azure DevOps tool name. |
   | Import from and Import to | Select the dates for which you want to import the pipeline and artifact data. By default, the last 30 days are selected. You can choose to import data for a maximum of 90 days. |
   | Repositories | Select the repositories for which you want to import historical data. |
   | Import from and Import to | Select the dates for which you want to import the Repositories data. By default, the last 30 days are selected. You can choose to import data for a maximum of 90 days. |
   | Onboarding plans | Enter the connected Azure DevOps tool name. |
   | Plans | Select the plans for which you want to import historical data. |
   | Import from and Import to | Select the dates for which you want to import the Plans data. By default, the last 30 days are selected. You can choose to import data for a maximum of 90 days. |
   [ ]

   {#onboard-azure-devops-service-catalog__table_vb5_s3p_gwb}
9. Select Order Now.  
   A request is created. When the request is approved, the plans, repositories, artifacts, and pipeline objects are associated to the app record and webhooks are configured for real-time tracking. Historical data is imported for the selected items. The Track field is automatically enabled for imported plans, repositories, and pipelines.

*[\>]: and then


