Microsoft Defender for Cloud DevOps Security
Configure Microsoft Defender for Cloud DevOps Security
Defender for Cloud DevOps security centralizes connected DevOps inventory and findings, then adds cloud context that can help teams prioritize remediation.
What it gives you
| Capability | Value |
|---|---|
| Supported environments | Azure DevOps Services · GitHub Enterprise Cloud · GitLab SaaS |
| Inventory and findings | Central visibility across connected repositories and supported scan results |
| Contextual prioritization | Relate code findings to cloud posture and runtime context where supported |
Scan paths and IaC mapping
The connector discovers inventory; it does not automatically enable every scanner. Findings can come from provider-native scanning such as GHAS, Microsoft Security DevOps in a pipeline, supported SARIF output published in the required CodeAnalysisLogs artifact, or preview agentless scanning where supported. Microsoft Security DevOps IaC results do not require a GHAS license.
IaC template-to-resource mapping is a narrower Azure DevOps path. It requires paid Defender CSPM, an onboarded Azure DevOps environment, Microsoft Security DevOps with IaCFileScanner, and unique yor_trace or mapping_tag GUID values on supported templates and resources.
Setting it up
- Onboard Defender for Cloud; enable paid Defender CSPM when advanced contextualization or IaC mapping requires it.
- Create and authorize the connector for the supported provider environment.
- Confirm repository discovery and inventory.
- Configure the intended scan path and its output—for example Microsoft Security DevOps plus
CodeAnalysisLogsfor Azure DevOps SARIF ingestion. - When IaC mapping is required, add
IaCFileScannerand the documented unique mapping tags.
Context can prioritize remediation and, for supported GitHub workflows, create issues or present a generated fix for developer review. It does not silently fix every finding.
Primary sources
- https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/az-400
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-devops-introduction
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/devops-support
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-azure-devops-extension
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/iac-vulnerabilities
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/agentless-code-scanning
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/iac-template-mapping
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-devops
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/github-advanced-security-deploy