No broader group (Contributors, Project Valid Users, Project Collection Build Service Accounts, etc.) should hold elevated allow bits at the project-default Build ACL. The scanner reads the Build security namespace and FAILs the control when any broad group has Edit, Delete, Administer, Override check-in, or other mutating permission allowed at the project root.
Remediation steps
- Open Pipelines > Builds and choose Manage security (project-default Build ACL).
- For each flagged broader group, set Edit / Delete / Administer / Override check-in validation to Not set or Deny.
- Leave View build pipeline / View builds at Allow only where required.
- Verify the flagged group can no longer modify or queue pipelines.
Microsoft Learn →