Copilot code review on Azure Repos needs three admins and it's still limited preview
The Azure DevOps buyer question keeps landing in my inbox: what's the best AI code review tool for Azure Repos? Almost every reviewer in this space shipped GitHub-first, so I went and read the primary docs instead of the comparison listicles. What I found is less a quality question than an availability one. On Azure Repos, whether your AI reviewer runs at all is a config lifecycle you own, not a…
Microsoft's Copilot code review on Azure Repos requires three separate administrators to be in place before it can function. These key roles are the Project Collection Administrator at the organization level, the Project Administrator at the project level, and either the Repository owner or administrator at the individual repository level. Additionally, individual users must opt-in to the preview feature, unless the admin enables it for everyone.
This multi-admin setup can be cumbersome, especially if your organization has a split between repo admins and platform teams, requiring cross-org ticket filings to test the preview feature. Furthermore, Copilot code review is currently in a limited preview, meaning its capabilities may change or be removed without notice, and it does not have a Service Level Agreement or limited support.
Azure Cost Management is used to bill for Copilot code review usage, with higher review effort levels consuming more tokens and potentially costing more. The admin controls the review effort level per repository, with a project-level default and per-repo overrides.
CodeRabbit, another AI reviewer option for Azure Repos, differs from Copilot in that it requires a Personal Access Token (PAT) that can expire silently. Connecting with a PAT tied to an Azure DevOps user, CodeRabbit does not have a native OAuth app for Azure DevOps integration. The recommended fix for PAT expiry issues is to create a dedicated service account with specific scopes and a rotation date on a shared calendar.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.