microsoft/AzureDevOps-WSJF-Extension

No security controls on WSJF Extension settings.

Opened this issue · 1 comments

We were expecting that the WSJF Extension settings https://dev.azure.com//_settings/MS-Agile-SAFe.WSJF-extension.wsjf-settings-hub would only be modifiable by Project Collection Administrators. We are finding that any user can make changes to the field mappings and Rounding settings. This is not acceptable to us. The ability to make changes must be locked down to members of Project Collection Administrators group.

Thank you for raising this concern. We understand the importance of restricting access to WSJF Extension settings. We appreciate your feedback and will update you once we have made the necessary adjustments. Thank you for your patience.