Spots

Copilot code review on Azure Repos needs three admins and it's still limited…

The Azure DevOps buyer question keeps landing in my inbox: what's the best AI code review tool for Azure Repos? Almost every reviewer in this space shipped GitHub-first, so I went and read the primary docs instead of the comparison listicles. What I found is less a quality question than an availability one. On Azure Repos, whether your AI reviewer runs at all is a config lifecycle you own, not a feature you install. Here's the actual shape of it on two tools people ask about most. Copilot code review on Azure Repos is a three-switch cascade

Microsoft's own prerequisites table for Copilot code review

Microsoft's own prerequisites table for Copilot code review spreads setup across four roles before Copilot can comment on a single pull request: A Project Collection Administrator enables it at the organization level. A Project Administrator enables it at the project level. A Repository owner or administrator enables it per repo. Individual users opt in through Preview features, unless the admin turns the preview on for everyone.

This is the part people miss when they

This is the part people miss when they compare feature checkboxes. On GitHub, you install an app and it reviews. On Azure Repos, three separate people with three different permission levels have to agree, in order, before the reviewer exists. If your org has the classic split where repo admins are team leads but org settings live with a platform team, that's a ticket you file across org boundaries just to try a preview feature.

And it is a preview. The doc says

And it is a preview. The doc says it plainly: "This feature is in limited preview", preview capabilities "might change or be removed without notice", and preview features "have no Service Level Agreement (SLA) and limited support". TFVC isn't supported either, only Git repos.

Then there's billing. Copilot code review usage is

Then there's billing. Copilot code review usage is billed through Azure Cost Management against an Azure subscription linked to the org, and the doc says higher "review effort" levels consume more tokens and can cost more. So the effort knob on a repository is a spend knob, set by an admin, with a project-level default and per-repo overrides that a project admin can allow or lock.

None of this is a knock on the

None of this is a knock on the model. It's just that availability and cost both live outside the PR, in three admin consoles, on a preview timeline. CodeRabbit trades those admins for a PAT that quietly expires

CodeRabbit is the other name that comes up

CodeRabbit is the other name that comes up for ADO shops, and it does support Azure Repos. The setup is documented in CodeRabbit's Azure DevOps platform docs, which call out two permission kinds: standard repository and work-item access, plus permission to manage service hooks (webhooks).

There's no native OAuth app for the Azure

There's no native OAuth app for the Azure DevOps integration. You connect with a Personal Access Token tied to an Azure DevOps user. A practitioner write-up on CodeRabbit + Azure DevOps setup notes spells out why that matters more than it sounds:

"When they do, CodeRabbit silently stops reviewing PRs

"When they do, CodeRabbit silently stops reviewing PRs. If the PAT belongs to an engineer who leaves the company, you lose code review across the org with no warning."

The recommended fix is a dedicated service account

The recommended fix is a dedicated service account, Reader at org level, Contributor on the repos you want reviewed, with scopes for Code (Read & Write), Pull Request Threads (Read & Write), Project and Team (Read), and User Profile (Read), and a rotation date on a shared calendar.

News

Copilot code review on Azure Repos needs three admins and it's still limited preview

The Azure DevOps buyer question keeps landing in my inbox: what's the best AI code review tool for Azure Repos?

@spots #dev
Source: Dev.to
See more like this