Integrating GHAS with Defender for Cloud
Integrate GitHub Advanced Security with Microsoft Defender for Cloud
Imported findings and Defender scan paths
| Path | Responsibility |
|---|---|
| Imported GHAS/CodeQL findings | CodeQL performs the analysis and creates code-scanning alerts; Defender ingests and correlates them with cloud/runtime context |
| Defender agentless code scanning | Defender retrieves and scans code, open-source dependencies, and infrastructure-as-code without pipeline changes |
| Microsoft Security DevOps | Runs supported security analysis inside the pipeline |
For imported GHAS findings, the integration's value is shared context: a code-level finding can be related to the affected cloud workload, repository, and ownership or status information. Do not generalize that path into “Defender never scans code,” because Defender has separately configured agentless and in-pipeline scanning paths.
Prerequisites, onboarding, and validation
The current GitHub GHAS integration prerequisites are:
- A GitHub account with a connector already created in Defender for Cloud
- GHAS licensing on the connected repositories
- Defender CSPM enabled on the subscription
Security Copilot is optional. These are prerequisites, not the old GHAS → plan → connector sequence.
The documented GitHub workflow is:
- In Environment settings, add a GitHub environment and enter connector details.
- Authorize GitHub, install the Defender for Cloud GitHub app, and select organizations.
- Review or generate the configuration and create the connector.
- Allow repository discovery, then locate the repository in DevOps security.
- Review findings and confirm Advanced Security status, ensure agentless scanning is enabled where required, and validate code-to-runtime results after processing.
These GitHub connector, campaign, issue, and optional coding-agent behaviors are GitHub-specific. GHAS for Azure DevOps ingestion has its own Azure DevOps setup path.
Remediation and troubleshooting
Inventory with no results does not prove one cause. Allow documented processing time, then check artifacts, scanner configuration, connector scope and permissions, and Advanced Security status.
Defender can coordinate remediation through GitHub issues, campaigns, shared ownership and status, plus optional proposed fixes. A developer still reviews and applies the change; it is not silently merged.
Primary sources
- https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/az-400
- https://docs.github.com/en/code-security/concepts/code-scanning/codeql/codeql-code-scanning
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/github-advanced-security-deploy
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-github
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/agentless-code-scanning
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/devops-support
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/github-advanced-security-overview