Azure Bugbot 授权与策略
为 Entra service principal 配置 tenant consent、Basic seat 和项目管理员权限。
Azure Bugbot 仅支持 Cursor team 的仓库,不支持 personal-scope 仓库。设置按 Azure DevOps organization 完成,再逐项目和仓库启用。
授权顺序
- Project Collection Administrator 在 Cursor 连接 Azure DevOps,并在 Bugbot 页面启用一个仓库,让 Cursor 发现 tenant 并配置 service principal。
- Entra 管理员完成一次 tenant admin consent;需要 Global Administrator、Application Administrator 或 Cloud Application Administrator。
- 确认 service principal 已加入 Azure organization 且获得 Basic access level。
- 每个 project 的管理员将它加入 Project Administrators group,随后启用目标仓库。
单纯 repository read 不够,因为管理 service hooks 需要项目管理权限。权限传播可能需要几分钟;刚授权后失败可等待传播后重试同一开关。
Consent 与 Basic access
Cursor 请求 Azure DevOps API 和标准登录 scopes,官方说明不请求 Microsoft Graph 数据。旧 consent 若未覆盖新增权限,重新连接账号也不够,需要重新打开官方 consent 流程刷新授权。
个人 Microsoft 账号支撑的组织不能创建此 service principal,需先连接 Entra ID。Cursor 使用已连接管理员自动添加 principal 和请求 Basic seat;失败时检查连接者能否添加用户,以及组织是否有可分配 Basic access。
触发与作者筛选
自动评审覆盖 PR 创建和更新,默认所有作者。手工评论 cursor review 或 bugbot run 只对 Azure 登录地址与仓库所属 Cursor team 账号邮箱匹配的人生效;同一个人的两个不同邮箱仍视为不同身份。
关闭 Run for All Authors 后可选择 Only Review PRs by 或 Skip PRs by,填写 Azure DevOps sign-in addresses,不是用户名。自动评审不受手工评论者邮箱匹配规则限制。
不同于其他服务商
仓库 settings 和手工 repository rules 生效,但当前不支持 Auto-Enable for New Repositories、Automatically Learn Rules、个人 Bugbot 设置或 Autofix。新仓库须逐个开启;关闭仓库或断开 Azure 连接会立即停止该仓库评审,关闭时移除 service hooks。
必需状态策略
Bugbot 发布的 build status context 是 cursor-bugbot/review。设为 required status 时,把 Reset conditions 改为 Reset status whenever there are new changes,否则旧提交的成功状态可能继续满足新提交策略。
旧安装迁移
2026 年 8 月前的 per-repository 设置可在组织管理员重新连接并再次启用仓库时自动迁移。若无法移除旧设置,在 Azure Project settings > Service hooks 中删除发送到 https://api2.cursor.sh/azure_devops_webhook 的旧 Cursor Web Hooks subscriptions,然后重新启用。
迁移后仍需 tenant consent、Basic seat 和各项目管理员组权限,不能把自动迁移当作免授权。