Skip to content

New admin controls, permission approval needed, and move-entries

Versions 2.0.37 and 2.0.38 · All release notes

We’ve published two updates to the Time Log extension for Azure DevOps. This release tightens security around the admin settings, introduces a handy way to tidy up disabled time types, and includes one action your Azure DevOps administrator needs to take to finish the update. Here’s everything you need to know.

  • ⚠️ Action required (administrators) — approve the updated permissions (v2.0.37)
  • 🔒 Time Log Admin is now restricted to Project Administrators (v2.0.37)
  • ↔️ Move time log entries from a disabled type to another type (v2.0.38)

🔒 Time Log Admin is now restricted to Project Administrators

Section titled “🔒 Time Log Admin is now restricted to Project Administrators”

The Time Log Admin page — and the Weekly shortfall report sub-page — are now limited to Project Administrators of the current project. This protects your time types, REST API key and settings from accidental or unauthorised changes.

Who still has access

  • Direct members of the project’s Project Administrators group.
  • Project Collection Administrators.
  • Members of Entra ID / Active Directory groups nested inside Project Administrators — nested (transitive) membership is recognised.

This works on both Azure DevOps Services (cloud) and Azure DevOps Server (on-premises).

What everyone else sees

Need access? Ask a project administrator to add you to the project’s Project Administrators group. After your membership changes, you may need to refresh your permissions (or sign out and back in) for Azure DevOps to recognise it.

↔️ Move entries from a disabled time type to another type

Section titled “↔️ Move entries from a disabled time type to another type”

When you disable a time type, its existing entries stay attached to it — which means you can’t delete it. You can now reassign all of a disabled type’s entries to a different, active type, so the old type can be fully drained and then removed.

How to move entries

  1. Open Project Settings → Extensions → Time Log Admin and find the Current Types table.
  2. Locate the disabled type (shown with a Disabled icon).
  3. Click the move icon on that row — its tooltip reads “Move entries to another type”.
  4. In the “Move time log entries” dialog, you can optionally use the “Show replacement types from” toggle — “This project” or “All projects” — to filter the list of candidates. This only changes which types you can pick from; every one of the disabled type’s entries is moved either way.
  5. Choose a Replacement type and click “Move entries”.
  6. You’ll see a confirmation such as “Moved 47 entries to Development. You can now delete the disabled type if it is no longer needed.”
  7. Delete the now-empty disabled type if you no longer need it.

Both the time type and the description on each moved entry are updated to the new type.

Lock the Time Log Admin page (and the Weekly Shortfall report sub-page) to Project Administrators of the current project. Non-admins now see a “Not authorised” panel instead of the admin UI. Membership is determined via the current user’s transitive membership in the project’s Project Administrators group — so Project Collection Administrators and members of AAD / Entra ID / on-prem AD groups nested inside Project Administrators are also recognised. On Azure DevOps Services (cloud) the direct-membership check uses the modern Graph API, with nested/transitive membership resolved via the Identity Service (_apis/identities?queryMembership=ExpandedUp on the SPS host); on Azure DevOps Server (verified on 2020 and 2022, where _apis/Graph/Descriptors 404s) the whole check transparently falls back to the legacy Identity Service, so the lockdown works on both. Every failure mode is strict default-deny: if neither the Graph API nor the Identity Service can verify membership, the user is treated as a non-admin until the install’s identity endpoints are fixed. Adds the vso.graph and vso.identity scopes to the extension manifest; existing customers will be prompted to re-consent on update.

Time Log Admin: add Move time log entries to another type for disabled time types. Each disabled type in the Current Types table gains a Move entries action that reassigns every time log entry using it to a different, active type (updating both the entry’s time type id and description). A Show replacement types from toggle filters the replacement list between the source type’s project and “All Projects” (organisation-level) types; all of the disabled type’s entries are moved regardless of the choice. This lets a disabled type be fully drained so it can then be deleted. Backed by a new REST endpoint POST /{organisationId}/timetype/{sourceTimeTypeId}/move-timelogs.