> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plerion.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Azure DevOps

> Integrate Plerion Code Security with Azure DevOps to scan repositories for infrastructure as code (IaC) issues and software composition analysis (SCA) issues directly in your development workflow.

With the [Azure DevOps integration](https://app.plerion.com/settings/integrations/add/Azure/AzureDevOps), you can connect your repositories to Plerion Code Security. This enables automatic scanning for IaC and SCA issues, giving developers early feedback and helping teams resolve issues before they reach production.

***

## Steps to integrate Azure DevOps with Plerion

<Steps>
  <Step title="On the Plerion dashboard, go to Settings > Integrations">
    <Frame>
      <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/settings-integrations-sidenav.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=66d327048296b04a1524638ea8dd1e18" alt="Plerion dashboard showing Settings expanded with Integrations selected" width="655" height="853" data-path="images/integrations/azure-devops/settings-integrations-sidenav.png" />
    </Frame>
  </Step>

  <Step title="Find Azure DevOps and click the + button">
    <Frame>
      <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/add-azure-devops-integration.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=f073ed5641c7a38330be2ab5ac743b7c" alt="Integrations page showing Azure DevOps tile with plus button" width="1294" height="890" data-path="images/integrations/azure-devops/add-azure-devops-integration.png" />
    </Frame>
  </Step>

  <Step title="Select a connection option and click Continue">
    Plerion connects to Azure DevOps using a service principal. Select **Connect with service principal** and click `Continue`.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/azure-devops-connection-options.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=aea311e97be96a622a66ff047db15fe0" alt="Connection options screen with Service Principal selected" width="3262" height="956" data-path="images/integrations/azure-devops/azure-devops-connection-options.png" />
    </Frame>
  </Step>

  <Step title="Enter a name for your integration">
    <Frame>
      <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/azure-devops-name-field.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=aa45ec2b60fb8e2e699d5ea81713db56" alt="Integration name field in Plerion Azure DevOps setup" width="1801" height="1203" data-path="images/integrations/azure-devops/azure-devops-name-field.png" />
    </Frame>
  </Step>

  <Step title="Enter your Application (client) ID and Directory (tenant) ID">
    These values come from your Azure app registration.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/azure-devops-app-and-tenant-id-fields.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=d66f9ac075de7cada88e36fd3ee8d2cb" alt="Application ID and Directory ID fields in Plerion Azure DevOps setup" width="1775" height="716" data-path="images/integrations/azure-devops/azure-devops-app-and-tenant-id-fields.png" />
    </Frame>
  </Step>

  <Step title="Enter your client secret and click Next">
    <Frame>
      <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/azure-devops-client-secret-and-next-button.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=6970cb3c5e5fb11575c238ad31434e8e" alt="Client secret field and Next button in Plerion Azure DevOps setup" width="1786" height="1102" data-path="images/integrations/azure-devops/azure-devops-client-secret-and-next-button.png" />
    </Frame>
  </Step>

  <Step title="Select the organization and click Next">
    <Note>
      If the Entra app has access to a single Azure DevOps organization, this step is skipped.
    </Note>

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/select-azure-devops-organization.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=cb0c2ce077a9df8f5e92f1fd12a21da6" alt="Organization selection screen in Plerion Azure DevOps setup" width="1802" height="437" data-path="images/integrations/azure-devops/select-azure-devops-organization.png" />
    </Frame>
  </Step>

  <Step title="After setup, you will be redirected to the Plerion platform">
    Your Azure DevOps integration is now active and ready to configure.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/azure-devops-integration-page.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=7f2df587cd66f77565b7427fe2e5b9df" alt="Plerion integration page showing Azure DevOps organization connected" width="1790" height="1229" data-path="images/integrations/azure-devops/azure-devops-integration-page.png" />
    </Frame>
  </Step>
</Steps>

***

## Configuring your Azure DevOps integration

Once installed, you can configure the Azure DevOps integration to suit your workflows. These options control when and how scans run, how findings are handled, and what rules apply.

### Integration status

Controls whether Plerion Code Security is active.

* **Default**: Enabled
* **When disabled**: Pauses all scanning activities, including scheduled and pull request scans
* **Recommendation**: Keep enabled unless there is a specific need to pause

<Frame>
  <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/integration-status.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=09563e1a298d2b27e8d7eabcdf3eacd5" alt="Integration status toggle in Plerion for Azure DevOps" width="1536" height="160" data-path="images/integrations/azure-devops/integration-status.png" />
</Frame>

### Scheduled scans

Runs automatic daily scans of your main branches.

* **Default**: Enabled
* **Purpose**: Ensures continuous monitoring of production-ready code
* **Key points**:
  * No manual input required
  * Helps identify risks over time
  * Best for stable branches

<Frame>
  <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/scheduled-scans.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=b459e48fcb0fd1836b50f337ef46196a" alt="Scheduled scans configuration in Plerion for Azure DevOps" width="1530" height="162" data-path="images/integrations/azure-devops/scheduled-scans.png" />
</Frame>

### Pull request scanning

Scans code in new and updated pull requests.

* **Default**: Enabled
* **What it does**:
  * Scans only changes in the pull request
  * Posts findings as comments in Azure DevOps
  * Uses Azure DevOps status checks to block insecure merges
* **Supported file types**: YAML, Terraform, JSON, and other IaC files
* **Why it matters**: Prevents findings from merging, encourages secure practices, and improves developer awareness

<Frame>
  <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/pull-request-scanning.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=c3c15007798bb9483d24246d1cd4fa14" alt="Pull request scanning configuration in Plerion for Azure DevOps" width="1540" height="164" data-path="images/integrations/azure-devops/pull-request-scanning.png" />
</Frame>

### Dismiss behavior

Controls how Plerion handles existing pull request comments when new commits are pushed.

<Frame>
  <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/dismiss-behavior.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=7603bbdeb596228372e61fcb105feba8" alt="Dismiss behavior configuration in Plerion for Azure DevOps" width="1538" height="200" data-path="images/integrations/azure-devops/dismiss-behavior.png" />
</Frame>

### Tolerance for blocking pull requests

Controls when pull requests are blocked based on severity.

* **Default**: Do not block pull requests
* **Options**:
  * Only block for critical findings
  * Block for high and critical findings
  * Block for medium and above findings
  * Block for any finding
  * Do not block pull requests
* **Best use**: Choose based on your team's risk tolerance, development velocity, and compliance needs

<Frame>
  <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/tolerance-configuration.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=17e661c7e398632e249a71c2b5d7f7d6" alt="Tolerance configuration options in Plerion for Azure DevOps" width="1522" height="202" data-path="images/integrations/azure-devops/tolerance-configuration.png" />
</Frame>

### Profile

Defines which detection rules are used during scans.

* **Default**: Organization's default profile
* **Options**: Use an existing profile or create a new one
* **Where to manage**: Detection Settings
* **Best use**: Align with coding standards, risk tolerance, and compliance needs

<Frame>
  <img src="https://mintcdn.com/pleriondocs/C1CbmNexZ9aQNkDc/images/integrations/azure-devops/profile.png?fit=max&auto=format&n=C1CbmNexZ9aQNkDc&q=85&s=5535d31f3a102b6d2e3fbfb7d494ef23" alt="Profile selection in Plerion Azure DevOps integration" width="1558" height="184" data-path="images/integrations/azure-devops/profile.png" />
</Frame>

***

## Best practices

* Keep the integration enabled for continuous coverage
* Use scheduled scans to secure long-term branches
* Enable PR scanning to prevent insecure code from merging
* Set PR blocking tolerance based on your security posture
* Select a detection profile that matches your organization's needs
