The Settings Menu (Pro)

The Settings section of the sidebar groups every administrative page in DefectDojo Pro. Which layout you see depends on when your instance was created:

  • New installations open on the reorganized layout described below.
  • Existing installations keep the previous layout until an administrator turns on Menu 2.0 (see Switching layouts).

Either way, every settings page keeps the same URL. Bookmarks, saved links and anything in your own runbooks continue to work regardless of which layout is active.

The reorganized layout

Settings is divided into seven groups, named for what you are trying to do rather than for the part of the system involved.

GroupWhat it holds
SystemSystem Settings, Appearance, Announcement Banner, Login Banner, E-mail, Feature Flags
Users & PermissionsUsers, Groups, Roles
Finding WorkflowThe three Deduplication pages, Finding Enrichment, Service Level Agreements, Prioritization Engines, Mitigation Policies
ConfigurationEnvironments, Regulations, Note Types, Test Types, CI/CD Infrastructure, Tool Types, Tool Configurations
NotificationsNotification Events, Notification Webhooks
OperationsAudit Logs, Usage Logs, Schedules, Celery Status, and — on DefectDojo Cloud — Message Portal, Firewall Rules, Maintenance Windows
License & SupportLicense Manager, Version Manager, Contact Support

You only ever see the entries your account has permission to open, and a group disappears entirely when none of its pages are available to you.

Two conventions are worth knowing:

  • There are no separate “New” entries. Each list page has a New button that opens the create form, so the menu carries one entry per catalog instead of two. If your account can create a record but not list them, the menu entry takes you straight to the create form.
  • Nothing nests more than one level below a group. Reaching a page is at most Settings → group → page.

All Settings

The first entry in the section, All Settings, opens a directory of every settings page your account can reach, arranged in the same groups as the menu and searchable by name or by what the page does. Searching deduplication finds the three deduplication pages and System Settings, because System Settings holds deduplication options too.

The last category, Elsewhere in the app, lists pages that configure DefectDojo but live in other sidebar sections — the authorization providers, Login and MFA settings, Jira instances, the Upstream and Downstream connectors, and the Universal Parser. Each tile is chipped with the section it belongs to.

What moved

If you are used to the previous layout:

PreviouslyNow
Settings → (top level) → Feature FlagsSettings → System → Feature Flags
Settings → Pro Settings → System SettingsSettings → System → System Settings
Settings → Pro Settings → AppearanceSettings → System → Appearance
Settings → Pro Settings → Banner Settings → Announcement Banner SettingsSettings → System → Announcement Banner
Settings → Pro Settings → Banner Settings → Login Banner SettingsSettings → System → Login Banner
Settings → Pro Settings → E-mail SettingsSettings → System → E-mail
Settings → Users → All Users / New UserSettings → Users & Permissions → Users
Settings → Users → All Groups / New GroupSettings → Users & Permissions → Groups
Settings → Users → RolesSettings → Users & Permissions → Roles
Settings → Pro Settings → Deduplication Settings → (three pages)Settings → Finding Workflow → Same Tool / Cross Tool / Reimport Deduplication
Settings → Pro Settings → Finding Enrichment SettingsSettings → Finding Workflow → Finding Enrichment
Settings → Configuration → Service Level AgreementsSettings → Finding Workflow → Service Level Agreements
Settings → Configuration → Prioritization EnginesSettings → Finding Workflow → Prioritization Engines
Settings → Configuration → Mitigation PoliciesSettings → Finding Workflow → Mitigation Policies
Settings → Configuration → (reference-data catalogs)Settings → Configuration → (unchanged)
Settings → Pro Settings → Notification SettingsSettings → Notifications
Settings → Configuration → Audit LogsSettings → Operations → Audit Logs
Settings → Configuration → Usage logSettings → Operations → Usage Logs
Settings → Configuration → All SchedulesSettings → Operations → Schedules
Settings → Pro Settings → Celery StatusSettings → Operations → Celery Status
Settings → Cloud Manager → (cloud pages)Settings → Operations
Settings → License Manager / Version Manager / Contact SupportSettings → License & Support

The group that was named after your license package — Pro Settings on a Pro instance, Enterprise Settings on an Enterprise one — no longer exists. Its pages are distributed across System, Finding Workflow, Notifications and Operations.

Switching layouts

Menu 2.0 on the Feature Flags page controls which layout is active. Turning it on or off reshapes the sidebar immediately; no restart is needed and nothing else about your instance changes.

New installations start with it on. Existing installations start with it off, so an upgrade never rearranges the menu under a team mid-flight — turn it on when your administrators are ready.

While it is off, the All Settings page is unavailable and its URL returns Not Found.