Troubleshoot adding members to projects
Azure DevOps Services | Azure DevOps Server 2019 | TFS 2018 | TFS 2017 | TFS 2015 | TFS 2013
Q: Why can't I add any more members to my project?
A: Your organization is free for the first five users with Basic access. You can add unlimited Stakeholders and Visual Studio subscribers for no extra charge. After you assign all five free users with Basic access, you can continue adding Stakeholders and Visual Studio subscribers.
To add six or more users with Basic access, you need to set up billing in Azure. Then you can pay for more users who need Basic access, return to your organization, add these users, and assign them Basic access. When billing is set up, you can pay monthly for the extra users' access. And you can cancel at any time.
If you need more Visual Studio subscriptions, learn how to buy subscriptions.
Q: Why can't some users sign in?
A: This problem might happen because users must sign in with Microsoft accounts unless your organization controls access with Azure Active Directory (Azure AD). If your organization is connected to Azure AD, users must be directory members to get access. See How do I find out if my organization uses Azure Active Directory (Azure AD)?
If you're an Azure AD administrator, you can add users to the directory. If you're not, work with the directory administrator to add them. Learn how to control organization access with Azure AD.
Q: Why can't users access some features?
A: Make sure that users have the correct access level assigned to them.
Some features are available only as extensions. You need to install these extensions. Most extensions require you to have at least Basic access, not Stakeholder access. Check the extension's description in the Visual Studio Marketplace, Azure DevOps tab.
For example, to search your code, you can install the free Code Search extension, but you need at least Basic access to use the extension.
To help your team improve app quality, you can install the free Test & Feedback extension, but you get different capabilities based on your access level and whether you work offline or connected to Azure DevOps Services or Team Foundation Server (TFS).
Some Visual Studio subscribers can use this feature for free, but Basic users need to upgrade to Basic + Test Plans access before they can create test plans.
- Learn how to get extensions for Azure DevOps.
- Learn how to get extensions for TFS.
- Learn how to buy access to TFS Test.
Q: Why did some users lose access to certain features?
A: Loss of access might happen for different reasons.
Q: How do I find out whether my organization uses Azure AD to control access?
A: If you have at least Basic access, here's how to find out:
Go your Organization settings, and then select the Azure Active Directory tab. See the following examples of an organization that is not connected, and then an organization that is connected to Azure AD.
If your organization is connected to your organization's directory, only users from your organization's directory can join your organization. Learn how to control organization access by using Azure AD.
Q: How do I remove users from my organization?
A: Learn how to delete users across all projects in your organization. If you paid for more users but don't need their organization access anymore, you must reduce your paid users to avoid charges.
Q: Why can't I find members from my connected Azure AD, even though I'm the Azure AD global admin?
A: You're probably a guest in the Azure AD instance that backs Azure DevOps. By default, Azure AD guests can't search in Azure AD. That's why you aren't finding users in your connected Azure AD to add to your organization.
First, check to see if you're an Azure AD guest:
Go to the Settings section of your organization. Look at the Azure Active Directory section at the bottom. Make a note of the tenant that backs your organization.
Sign in to the new Azure portal, portal.azure.com. Check your user profile in the tenant from step 1. Check the User type value shown as follows:
If you're an Azure AD guest, do one of the following:
- Have another Azure DevOps admin, who isn't an Azure AD guest, manage the users in Azure DevOps for you. Members of the Project Collection Administrators group inside Azure DevOps can administer users.
- Have the Azure AD admin remove you from the connected Azure AD and re-add you. The admin needs to make you an Azure AD member rather than a guest. See Can Azure AD B2B users be added as members instead of guests?
- Change the User Type of the Azure AD guest by using Azure AD PowerShell. This is an advanced topic, and we don't advise it. But it works and allows the user to query Azure AD from Azure DevOps thereafter.
Open PowerShell and run the following cmdlets.
a. Connect to Azure AD:
b. Find the objectId of the user:
c. Check the usertype attribute for this user to see if they're a guest or member:
C:\Users\rajr> Get-AzureADUser -objectId cd7d47bf-1c6e-4839-b765-13edcd164e66
d. Change the usertype from member to guest:
C:\Users\rajr> Set-AzureADUser -objectId cd7d47bf-1c6e-4839-b765-13edcd164e66 -UserType Member
Q: Why don't users appear or disappear promptly in Azure DevOps after I add or delete them in the Users hub?
A: If you experience delays finding new users or having deleted users promptly removed from Azure DevOps (for example, in drop-down lists and groups) after you add or delete users, file a problem report on Developer Community so we can investigate.
Q: Why do I have to choose between a "work or school account" and my "personal account"?
A: This happens when you sign in with an email address (for example, email@example.com) that's shared by your personal Microsoft account and by your work account or school account. Although both identities use the same sign-in address, they're still separate identities. The two identities have different profiles, security settings, and permissions.
Select Work or school account if you used this identity to create your organization, or if you previously signed in with this identity. Your identity is authenticated by your organization's directory in Azure AD, which controls access to your organization.
Select Personal account if you used your Microsoft account with Azure DevOps. Your identity is authenticated by the global directory for Microsoft accounts.
Q: Why can't I sign in after I select "personal Microsoft account" or "work or school account"?
A: When your sign-in address is shared by your personal Microsoft account and by your work account or school account, but your selected identity doesn't have access, you can't sign in. Although both identities use the same sign-in address, they're separate: they have different profiles, security settings, and permissions.
Sign out completely from Azure DevOps by completing the following steps. Closing your browser might not sign you out completely. Sign in again and select your other identity:
Close all browsers, including browsers that aren't running Azure DevOps.
Open a private or incognito browsing session.
Go to this URL:
You see a message that says, "Sign out in progress." After you sign out, you're redirected to the Azure DevOps @dev.azure.microsoft.com webpage.
If the sign-out page takes more than a minute to sign you out, close the browser and continue.
Sign in to Azure DevOps again. Select your other identity.
Q: How do I find a Project Collection Administrator?
A: If you have at least Basic access, you can find your Project Collection Administrator in your organization's security settings.
Q: How do I find the organization owner?
If you have at least Basic access, you can find the current owner in your organization settings.
Go to your Organization settings.
Find the current owner.
Q: How do I get help or support for Azure DevOps?
A: You have the following options for support: