Connect a GitHub Enterprise instance to SSPM to detect posture risks.
For SSPM to detect posture risks in your GitHub Enterprise instance, you must onboard
your GitHub Enterprise instance to SSPM. Through the onboarding process, SSPM logs
in to GitHub Enterprise using administrator account credentials. SSPM uses this
account to scan your GitHub Enterprise instance for misconfigured settings. If there
are misconfigured settings, SSPM suggests a remediation action based on best
practices.
The GitHub Enterprise administrator account must be configured for multi-factor
authentication (MFA), which adds an extra layer of security by requiring a one-time
passcode to access the account.
To onboard your GitHub Enterprise instance, you complete the following actions: