Edit

Share via


Support and prerequisites: DevOps security

This article summarizes support information for DevOps security capabilities in Microsoft Defender for Cloud.

Cloud and region support

DevOps security is available in the Azure commercial cloud, in these regions:

  • Asia (East Asia)
  • Australia (Australia East)
  • Canada (Canada Central)
  • Europe (West Europe, North Europe, Sweden Central)
  • UK (UK South)
  • US (East US, Central US)

DevOps platform support

DevOps security currently supports the following DevOps platforms:

Required permissions

DevOps security requires the following permissions:

Feature Permissions
Connect DevOps environments to Defender for Cloud
  • Azure: Subscription Contributor or Security Admin
  • Azure DevOps: Project Collection Administrator on target Organization
  • GitHub: Organization Owner
  • GitLab: Group Owner on target Group
Review security insights and findings Security Reader
Configure pull request annotations Subscription Contributor or Owner
Install the Microsoft Security DevOps extension in Azure DevOps Azure DevOps Project Collection Administrator
Install the Microsoft Security DevOps action in GitHub GitHub Write

Note

Security Reader role can be applied on the Resource Group or connector scope to avoid setting highly privileged permissions on a Subscription level for read access of DevOps security insights and findings.

Feature availability

DevOps security capabilities, such as code-to-cloud contextualization, security explorer, attack path analysis, and pull request annotations for Infrastructure-as-Code security findings, are available when you enable the paid Defender Cloud Security Posture Management (CSPM) plan.

The following tables summarize the availability and prerequisites for each feature within the supported DevOps platforms:

Azure DevOps

GitHub

GitLab