You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
| Connect DevOps environments to Defender for Cloud | <ul><li>Azure: Subscription Contributor or Security Admin</li><li>Azure DevOps: Project Collection Administrator on target Organization</li><li>GitHub: Organization Owner</li><li>GitLab: Group Owner on target Group</li></ul> |
37
37
| Review security insights and findings | Security Reader |
@@ -47,8 +47,7 @@ DevOps security requires the following permissions:
47
47
The following tables summarize the availability and prerequisites for each feature within the supported DevOps platforms:
48
48
49
49
> [!NOTE]
50
-
> Starting March 7, 2024, [Defender CSPM](concept-cloud-security-posture-management.md) must be enabled to have premium DevOps security capabilities which include code-to-cloud contextualization powering security explorer and attack paths and pull request annotations for Infrastructure-as-Code security findings. See details below to learn more.
51
-
50
+
> Starting March 7, 2024, [Defender CSPM](concept-cloud-security-posture-management.md) must be enabled on at least one subscription or multicloud connector in the tenant to benefit from premium DevOps security capabilities which include code-to-cloud contextualization powering security explorer and attack paths and pull request annotations for Infrastructure-as-Code security findings. See details below to learn more.
@@ -62,8 +61,8 @@ The following tables summarize the availability and prerequisites for each featu
62
61
|[Pull request annotations](review-pull-request-annotations.md)||| See [here](enable-pull-request-annotations.md)|
63
62
|[Code to cloud mapping for Containers](container-image-mapping.md)|||[Microsoft Security DevOps extension](azure-devops-extension.md#configure-the-microsoft-security-devops-azure-devops-extension-1)|
64
63
|[Code to cloud mapping for Infrastructure as Code templates](iac-template-mapping.md)|||[Microsoft Security DevOps extension](azure-devops-extension.md)|
65
-
|[Attack path analysis](how-to-manage-attack-path.md)|||Enable Defender CSPM on the Azure DevOps connector|
66
-
|[Cloud security explorer](how-to-manage-cloud-security-explorer.md)|||Enable Defender CSPM on the Azure DevOps connector |
64
+
|[Attack path analysis](how-to-manage-attack-path.md)|||Enable Defender CSPM on an Azure Subscription, AWS Connector, or GCP Connector in the same tenant as the DevOps Connector|
65
+
|[Cloud security explorer](how-to-manage-cloud-security-explorer.md)|||Enable Defender CSPM on an Azure Subscription, AWS Connector, or GCP connector in the same tenant as the DevOps Connector|
67
66
68
67
69
68
### GitHub
@@ -78,8 +77,8 @@ The following tables summarize the availability and prerequisites for each featu
|[Code to cloud mapping for Containers](container-image-mapping.md)|||[Microsoft Security DevOps action](github-action.md)|
80
79
|[Code to cloud mapping for Infrastructure as Code templates](iac-template-mapping.md)|||[Microsoft Security DevOps action](github-action.md)|
81
-
|[Attack path analysis](how-to-manage-attack-path.md)||| Enable Defender CSPM on the GitHub connector |
82
-
|[Cloud security explorer](how-to-manage-cloud-security-explorer.md)||| Enable Defender CSPM on the GitHub connector |
80
+
|[Attack path analysis](how-to-manage-attack-path.md)||| Enable Defender CSPM on an Azure Subscription, AWS Connector, or GCP connector in the same tenant as the DevOps Connector|
81
+
|[Cloud security explorer](how-to-manage-cloud-security-explorer.md)||| Enable Defender CSPM on an Azure Subscription, AWS Connector, or GCP connector in the same tenant as the DevOps Connector|
83
82
84
83
85
84
### GitLab
@@ -91,4 +90,4 @@ The following tables summarize the availability and prerequisites for each featu
91
90
|[Security recommendations to discover exposed secrets](defender-for-devops-introduction.md#manage-your-devops-environments-in-defender-for-cloud)|||[GitLab Ultimate](https://about.gitlab.com/pricing/ultimate/)|
92
91
|[Security recommendations to fix open source vulnerabilities](defender-for-devops-introduction.md#manage-your-devops-environments-in-defender-for-cloud)|||[GitLab Ultimate](https://about.gitlab.com/pricing/ultimate/)|
93
92
|[Security recommendations to fix infrastructure as code misconfigurations](defender-for-devops-introduction.md#manage-your-devops-environments-in-defender-for-cloud)|||[GitLab Ultimate](https://about.gitlab.com/pricing/ultimate/)|
94
-
|[Cloud security explorer](how-to-manage-cloud-security-explorer.md)||| Enable Defender CSPM on the GitLab connector |
93
+
|[Cloud security explorer](how-to-manage-cloud-security-explorer.md)||| Enable Defender CSPM on an Azure Subscription, AWS Connector, or GCP connector in the same tenant as the DevOps Connector|
0 commit comments