Microsoft Defender for Cloud DevOps security benefits - Microsoft Defender for Cloud (original) (raw)

Microsoft Defender for Cloud enables comprehensive visibility, posture management, and threat protection across multicloud environments, including Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), and on-premises resources.

DevOps security in Defender for Cloud uses a central console to help security teams protect applications and resources from code to cloud across multi-pipeline environments, including Azure DevOps, GitHub, and GitLab. DevOps security recommendations can be correlated with other contextual cloud security insights to prioritize remediation in code. Key DevOps security capabilities include:

These features help unify, strengthen, and manage multi-pipeline DevOps resources.

Manage your DevOps environments in Defender for Cloud

DevOps security in Defender for Cloud lets you manage your connected environments. It provides your security teams with a high-level overview of issues discovered in those environments through the DevOps security console.

Screenshot of the top of the DevOps security page that shows all of your onboarded environments and their metrics.

Here, you can add Azure DevOps, GitHub, and GitLab environments, customize the DevOps workbook to show your desired metrics, configure pull request annotations, view our guides, and give feedback.

Understand your DevOps security

Page section Description
Screenshot of the scan finding metrics sections of the page. Total number of DevOps security scan findings (code, secrets, dependency, infrastructure-as-code) grouped by severity level and by finding type.
Screenshot of the DevOps environment posture management recommendation card. Provides visibility into the number of DevOps environment posture management recommendations highlighting high severity findings and number of affected resources.
Screenshot of DevOps advanced security coverage per source code management system onboarded. Provides visibility into the number of DevOps resources with advanced security capabilities out of the total number of resources onboarded by environment.

Review your findings

The DevOps inventory table lets you review onboarded DevOps resources and their related security information.

Screenshot that shows the DevOps inventory table on the DevOps security overview page.

In this section, you see:

You can view this table as a flat view at the DevOps resource level (repositories for Azure DevOps and GitHub, projects for GitLab) or in a grouping view showing organizations, projects, and groups hierarchy. You can also filter the table by subscription, resource type, finding type, or severity.

Learn more