The GitHub connector in Microsoft Defender for Cloud DevOps Security shows Connected, but the critical lock-lab repository still has no findings. What should the Azure security engineer do next?
Select an answer to reveal the explanation.
Short Explanation
“Connected” isn’t the finish line. Open the DevOps Security settings, pick the orgs and repos that matter—including that lock-lab repo—and finish the app authorization so findings actually show up.
Full Explanation
A Connected status alone does not guarantee every repository is in scope. Microsoft Defender for Cloud DevOps Security requires configuring which organizations, projects, and repositories are onboarded and completing the application authorization. Until those settings include the critical repository, findings will not appear for it. Recreating the Defender for Cloud environment or switching to an unsupported host does not fix incomplete connector scope.