Lesson349 words

Integrating GHAS with Defender for Cloud

Integrate GitHub Advanced Security with Microsoft Defender for Cloud

Imported findings and Defender scan paths

PathResponsibility
Imported GHAS/CodeQL findingsCodeQL performs the analysis and creates code-scanning alerts; Defender ingests and correlates them with cloud/runtime context
Defender agentless code scanningDefender retrieves and scans code, open-source dependencies, and infrastructure-as-code without pipeline changes
Microsoft Security DevOpsRuns supported security analysis inside the pipeline

For imported GHAS findings, the integration's value is shared context: a code-level finding can be related to the affected cloud workload, repository, and ownership or status information. Do not generalize that path into “Defender never scans code,” because Defender has separately configured agentless and in-pipeline scanning paths.

Prerequisites, onboarding, and validation

The current GitHub GHAS integration prerequisites are:

  • A GitHub account with a connector already created in Defender for Cloud
  • GHAS licensing on the connected repositories
  • Defender CSPM enabled on the subscription

Security Copilot is optional. These are prerequisites, not the old GHAS → plan → connector sequence.

The documented GitHub workflow is:

  1. In Environment settings, add a GitHub environment and enter connector details.
  2. Authorize GitHub, install the Defender for Cloud GitHub app, and select organizations.
  3. Review or generate the configuration and create the connector.
  4. Allow repository discovery, then locate the repository in DevOps security.
  5. Review findings and confirm Advanced Security status, ensure agentless scanning is enabled where required, and validate code-to-runtime results after processing.

These GitHub connector, campaign, issue, and optional coding-agent behaviors are GitHub-specific. GHAS for Azure DevOps ingestion has its own Azure DevOps setup path.

Remediation and troubleshooting

Inventory with no results does not prove one cause. Allow documented processing time, then check artifacts, scanner configuration, connector scope and permissions, and Advanced Security status.

Defender can coordinate remediation through GitHub issues, campaigns, shared ownership and status, plus optional proposed fixes. A developer still reviews and applies the change; it is not silently merged.

Primary sources

Ready to study Designing and Implementing Microsoft DevOps Solutions (AZ-400)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free