Skip to main content
Cloud / Azure / Products / GitHub Advanced Security for Azure DevOps

GitHub Advanced Security for Azure DevOps

GitHub Advanced Security for Azure DevOps brings code scanning and secret detection to Azure Repos.

devops
Pricing Model Per active committer per month (billed separately for Secret Protection and Code Security)
Availability Azure DevOps Services (cloud) only; Azure DevOps Server on-premises is not supported
Data Sovereignty Azure DevOps data residency
Reliability Azure DevOps SLA (see official SLA page) SLA

What is GitHub Advanced Security for Azure DevOps?

GitHub Advanced Security for Azure DevOps brings the same CodeQL-based scanning capabilities from GitHub to Azure Repos. It enables teams already using Azure DevOps to benefit from code scanning, secret detection, and dependency scanning without migrating to GitHub.

The feature set is now offered as two separately activated and billed products: GitHub Secret Protection for Azure DevOps (push protection, secret scanning alerts, security overview) and GitHub Code Security for Azure DevOps (dependency alerts, CodeQL scanning, security findings from third-party tools). Organizations can enable either product independently at the repository, project, or organization level.

Security results appear directly in the Azure DevOps interface: in pull requests, the repository overview, and organization-wide dashboards. Teams can keep existing workflows and additionally configure status checks that block pull requests when critical or high-severity vulnerabilities are found.

Core Features

  • Code scanning: CodeQL static analysis, configurable via default or advanced setup, detects vulnerabilities in your code
  • Secret scanning and push protection: identifies credentials committed to Azure Repos and blocks pushes that expose secrets
  • Dependency scanning: flags vulnerable open-source dependencies, direct and transitive
  • PR annotations and status checks: security findings appear as pull request comments, with optional merge-blocking checks
  • Security overview / dashboard: organization-wide view of security alerts and risk posture

Typical Use Cases

This service is designed for organizations that have invested in Azure DevOps and want enterprise security scanning without changing their source control platform. It is particularly relevant for teams in regulated industries that need documented security controls.

Benefits

  • Same CodeQL engine used by GitHub code scanning
  • No migration from Azure Repos required
  • Integrated into existing Azure Pipelines and pull request workflows
  • Secret Protection and Code Security can be enabled independently based on need
  • Unified licensing and billing through Azure DevOps

Frequently Asked Questions

Do we need a GitHub account to use this?

No. GitHub Advanced Security for Azure DevOps runs entirely within Azure DevOps. You do not need GitHub repositories or GitHub accounts.

What is the difference between Secret Protection and Code Security?

Secret Protection covers push protection and secret scanning alerts. Code Security covers CodeQL code scanning and dependency scanning. Both are billed separately per active committer and can be enabled independently.

How does secret scanning differ from Azure Key Vault?

Secret scanning detects secrets accidentally committed to source code. Key Vault is a secure store for secrets your applications need at runtime. They serve different purposes and are often used together.

Can we use custom CodeQL queries?

Yes. You can add custom CodeQL queries in advanced setup to detect organization-specific vulnerability patterns or enforce coding standards.

Integration with innFactory

As a Microsoft Solutions Partner, innFactory helps you enable GitHub Advanced Security in Azure DevOps: pipeline configuration, custom queries, and security policy implementation.

Typical Use Cases

Code scanning in Azure Repos
Secret detection and push protection in Azure DevOps
Dependency scanning for Azure Pipelines
Security compliance for regulated industries

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with GitHub Advanced Security for Azure DevOps?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation