An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
For Azure DevOps-style view-only access, add the person to a Readers group so they can view content without edit rights.
If dashboard access is also needed without allowing changes:
- Go to Azure DevOps Project Settings > Teams.
- Create a new team and add the person as a member.
- Go to Project Settings > Dashboards.
- Select that new team.
- Turn off Edit dashboard and Delete Dashboard.
- Remove the person from any other team that still has dashboard edit permissions enabled.
For test-related visibility, the Readers group allows viewing work items and test plans. The accepted guidance also notes that basic access is needed to view dashboards and test plans.