Which Defender CLI binary should be used in CI/CD pipelines — `aka.ms` or the DevOps CDN endpoint?
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
Research direction
Start with the MicrosoftDefenderCLI@2 task and the linked Defender CLI install, syntax, and CI/CD documentation, then compare the documented aka.ms binary with the cli.dfd.security.azure.com endpoint. Done means establishing whether the CDN is supported and stable, whether the binaries are separate products, and which one Azure DevOps pipelines should use.
Written by the indexing model from the issue text.
Description
We're integrating Defender for Cloud image scanning into our Azure DevOps pipelines. Rather than using the MicrosoftDefenderCLI@2 task (which emits ##[error] for any findings regardless of the break setting), we're invoking the CLI binary directly so we can control exit code handling and surface findings as warnings.
We've discovered there are two different CLI binaries available:
Official (aka.ms) |
DevOps CDN | |
|---|---|---|
| URL | https://aka.ms/defender-cli_linux-x64 |
https://cli.dfd.security.azure.com/public/v2/latest/Defender_linux-x64 |
| Size | ~126 MB | ~24 MB |
| Version | v2.0.3334.114 (as of May 2026) | Unknown — no --version output tested |
| Break flag | --defender-break (critical only) |
--fail-on <severity> (configurable threshold) |
| Documented | Yes — Install, Syntax, CI/CD | No |
| Auth | Token-based (client ID/secret) or connector | Auto-detects SYSTEM_ACCESSTOKEN |
| SHA-256 | 79F4F1EDC1DD2F99193BFFC47464023A450CFEFA03F362D7716A5E51D357B0C1 |
CD31528812D19142DC58DEEA0475E2610F5CC4E4D036F78EAB2FF1243CC5BB3A |
Observations
-
The CDN binary appears purpose-built for CI/CD use. It's significantly smaller (24 MB vs 126 MB), supports a configurable severity threshold (
--fail-on low|medium|high|critical), and auto-detects Azure DevOps pipeline authentication viaSYSTEM_ACCESSTOKEN. The URL pattern (cli.dfd.security.azure.com/public/v2/latest/) suggests it's the same binary theMicrosoftDefenderCLI@2task downloads internally. -
The
aka.msCLI is the documented standalone CLI. It's referenced in the official CI/CD integration guide for non-ADO platforms (GitHub Actions, Jenkins, etc.). Its--defender-breakflag only exits non-zero for "critical issues" with no configurable threshold. -
The
--helpoutputs are completely different. The CDN binary exposes flags like--fail-on,--baseline,--severity,--suppress,--quiet, and--timeoutthat don't exist in theaka.msbinary, and vice versa (e.g.--defender-debug,--defender-outputonly inaka.ms). -
Neither binary's
scan imageflags match the documented CLI reference exactly. The docs list--defender-breakand--defender-outputas global options, which align with theaka.msbinary but not the CDN one.
Questions
-
Is the CDN endpoint (
cli.dfd.security.azure.com) a supported, stable distribution channel? Can we rely on it in production pipelines, or is it an internal implementation detail of the ADO task that could change without notice? -
Are these intended to be two separate products, or are they converging? The feature sets (especially
--fail-onvs--defender-break) suggest they may be independently developed. -
For Azure DevOps pipelines where we need to bypass the task wrapper (to avoid
##[error]on non-critical findings), which binary is recommended?
- Dominant language
- TypeScript
- Stars
- 86
- Forks
- 22
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from microsoft/security-devops-azdevops
-
Difficulty 1/5 Under an hour Newbie friendliness 68/100
-
area:task area:tools status:waiting-on-author type:docs type:question
microsoft/security-devops-azdevops#169 · 1 comment · 1 assignee ·
-
area:task area:tools status:team-review type:feature
microsoft/security-devops-azdevops#164 · 2 reactions · 2 assignees ·
-
area:task area:tools status:team-review type:docs type:feature
microsoft/security-devops-azdevops#163 · 17 comments · 1 assignee ·
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 35/100
microsoft/security-devops-azdevops#152 · 2 comments ·
All issues in microsoft/security-devops-azdevops
Similar issues
-
comp/desktop P3 type/bug
Difficulty 1/5 Under an hour Newbie friendliness 92/100
NousResearch/hermes-agent#118866 ·
-
Browser Waiting for: Product Owner
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
getsentry/sentry-javascript#24577 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
agilepathway/label-checker#640 ·
-
Plugin stuck at "loading" on DSH 0.1.6-alpha.2 — turnTail list slot registration missing options.id Open
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
chrisparsons83/flexspotff#153 ·