If you manage Azure DevOps in your organisation, there’s an important change coming. From 28 July 2025, Azure DevOps will stop relying on Azure Resource Manager (ARM) for sign-ins and token refresh. Any Conditional Access policies targeting ARM will no longer protect Azure DevOps.
To maintain security, you must create new Conditional Access policies that specifically target Azure DevOps.
Why Does This Matter? Conditional Access enforces multi-factor authentication, location restrictions, and device compliance for cloud services.
Continue reading