Home > Get Started > Enable Backup for Azure DevOps > Default Permissions Granted to the Service App
Export to PDFIf you want to protect Azure DevOps, you can choose to create a Cloud Backup for Azure DevOps service app profile or create a custom Azure app profile with delegated permissions through AvePoint Online Services > Management > App management page.
The following API permissions will be automatically added to the service app with consent from your Global administrator account. You can also choose the specific permissions to grant your custom Azure app for the services or data types that you want to protect upon the usage purpose. Currently, the required permissions don’t have any alternative permissions.
| API | Permissions | Type | Why You Need | Permission Category |
|---|---|---|---|---|
| Azure DevOps | user_impersonation(Have full access to Visual Studio Team Services REST APIs) | Delegated | Have full access to Visual Studio Team Services REST APIs. | Azure DevOps |
| Microsoft Graph | User.Read.All(Read all user’s full profile) | Delegated | Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user. | Sign into AvePoint Online Services with Microsoft 365 accounts. |