# ADO Service Principal

We usually provide temporary access of 6 hours for user to have the Application Admin role to perform below step on ADO to create the Service Principal required

<img src="https://2627915664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC5L8BFhTKgXFngIiQkEm%2Fuploads%2FQ81RgJIjWuxjAM3ArF0G%2Fimage.png?alt=media&#x26;token=1184f45f-74c2-4321-9079-5bdf092e180d" alt="" data-size="original">

<figure><img src="https://2627915664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC5L8BFhTKgXFngIiQkEm%2Fuploads%2F1saapE6nqGZBvlEmWHCe%2FMicrosoftTeams-image%20(17).png?alt=media&#x26;token=66cb1491-0329-430a-b2ec-7e8c20bc54cb" alt=""><figcaption></figcaption></figure>

However, we can also consider creating a custom role with the following permission to create an Application but not manage applications like adding API permissions. (Emily Wen - MSFT)

### Secrets in ADO

Get pipeline URL and get advice from either Brian/Gamer

![](https://2627915664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC5L8BFhTKgXFngIiQkEm%2Fuploads%2FLLf5537Jy3bKbRTAn5Hu%2Fimage.png?alt=media\&token=7d579a83-8b09-4488-a95f-c3f1b5017549)![](https://2627915664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC5L8BFhTKgXFngIiQkEm%2Fuploads%2FVX1yV7RTQnwwIZT4faGG%2Fimage.png?alt=media\&token=742bbd75-a9ce-48a4-80c3-00420f6b209a)![](https://2627915664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC5L8BFhTKgXFngIiQkEm%2Fuploads%2F1YLuPIeCsrBoJA3cr1Gg%2Fimage.png?alt=media\&token=bbb997cb-4360-4aaa-afd7-d4510fa0fbc4)
