You want to enforce an enterprise policy that allows repository administrators within all organizations to enable GitHub Advanced Security for their repositories. Which option should you choose for this policy?
The Allow for all organizations policy permits repository administrators throughout organizations owned by the enterprise to enable applicable Advanced Security capabilities on their repositories. GitHub enterprise policy can determine whether repository administrators are allowed to enable GitHub Secret Protection, GitHub Code Security, or legacy GitHub Advanced Security features. Selecting an option limited to chosen organizations would restrict availability rather than permit it enterprise-wide. A prohibition such as Never allow would prevent repository administrators from enabling the feature, while No policy does not explicitly establish the enterprise-wide permission requested. GitHub's current documentation describes this policy as controlling availability across all organizations or specified organizations, with organization owners and security managers retaining broader security-management capabilities. Therefore, B matches the stated requirement to allow repository administrators throughout all enterprise organizations.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit