Forum Discussion
Copilot Connector for DevOps - Crawl Account = Search Admin?
Hi all,
We’re about to set up Copilot Connectors for Azure DevOps (ADO) Wikis and Work Items across multiple organizations. During this process, we discovered that the account used to create the connector—requiring the Search Administrator role—is automatically designated as the crawl account. This crawl account must have read access across all projects within the ADO organization.
Currently, we’re using our individual user accounts (with Search Administrator privileges) to create the connectors. However, we cannot use these accounts as crawl accounts due to access limitations. Ideally, the crawl account should be a service account with the necessary read permissions.
The issue is that Microsoft’s configuration appears to require the same account to both create the connector and act as the crawl account. This would mean logging in with a service account that has Search Administrator rights, which is not a viable or secure option for us.
Are we misunderstanding the setup? Is there a way to use our own accounts to create the connector and then specify a separate service account as the crawl account during configuration?
We’re hoping someone can confirm that this separation is possible—and that we don’t need to grant Search Administrator privileges to a service account just to complete connector setup.
Thanks - Grant.