Microsoft Security Exposure Management
Vulnerabilities and exposure

Getting Started with Codename MDASH

In brief

The onboarding requirements now support remote scanning through either GitHub or Azure DevOps, refer to a linked list of required models, and document two authentication methods for the Foundry project endpoint. Detailed RBAC requirements are now provided through linked guidance.

What Defender admins need to know

Review the onboarding prerequisites and linked guidance when configuring MDASH, including the selected connector, Foundry authentication method, model deployments, and user permissions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

To complete this setup, you need:

  • Global Administrator or Security Administrator role in Microsoft Entra ID to complete the agentic code security onboarding process in the Microsoft Defender portal.

  • Authority to accept the codename MDASH terms and conditions on behalf of your organization during onboarding.

  • An Azure subscription and resource group in which to create a dedicated Microsoft Foundry resource used exclusively for codename MDASH. For full details, see Connect Microsoft Foundry.

  • Permission to deploy the following models with the Global Standard deployment type (all three are required):

    • gpt-5.4
    • gpt-5.3-codex
    • gpt-5.4-mini
  • A dedicated Foundry endpoint used exclusively for codename MDASH.required. For list of models, see Deploy the required models.

  • If the Foundry resource's networking is set to Selected networks and private endpoints, action is required to allow Codenamecodename MDASH access. For more information, see Allow Codename MDASH to access your Microsoft Foundry resource.

  • At least one of the following AI scanning paths. You can add the other later:paths:

    • Option 1 — Remote scan (GitHub connector, recommended)(recommended). For full details, see either Create a GitHub connector. You need:

      • Access to the Microsoft Defender portal with permission to create and manage connectors.
        • To create and manage connectors, you need the Global Administrator or Security Administrator role in Microsoft Entra ID.
        Create Azure DevOps connector.
      • Owner of the GitHub organization you want to connect.
      • Cloud Security prepared in the tenant (Cloud security > Overview > Prepare my tenant).
    • If the target GitHub organization is already connected through the Azure portal's GitHub connector, see the note in Create a GitHub connector.

      Option 2 — Defender CLI. For full details, see Defender CLI setup. You need:

      • Azure CLI installed.
      • The Microsoft Defender Code enterprise application installed in your tenant (automatic on E5 tenants; otherwise run the provided consent script).
      • The Defender CLI binary for your platform (Windows, macOS, or Linux). For more information, see Install Defender CLI.
      • To handle onboarding for app-based (client secret) authentication: Application Administrator in Microsoft Entra ID and a Global Administrator available to grant admin consent.
      • To handle onboarding for interactive authentication: Security Administrator in Microsoft Entra ID.
      • Users who perform local interactive scans require the Run scan (Manage) permission.
      • The Upload results (Manage) permission is required only for scenarios that involve uploading scan results.
    • If outbound traffic is restricted, allow the required domains. For more information, see Allow list.

    • Access to the Microsoft Defender portal with permission to open Exposure Management and Initiatives.

    • The Foundry project endpoint and API key fromendpoint. MDASH supports two authentication methods for the Foundry setup step.connection. For details about the available authentication methods, see Authentication methods.

    • Defender unified RBAC permissions assigned. Grant each user onlyFor the required permissions they need:

      • Run scan (Manage) — requiredand how to trigger on-demand or CLI scans.
      • Upload results (Manage) — required to upload CLI scan results to Defender.
      • Scan results (Read) — required to view findings in the Defender portal and the initiative.
      • Scan results (Manage) — required to triage, dismiss, or otherwise manage findings.

      For more information,assign them, see Assign permissions to users using Defender RBAC.

    Assign permissions to users using Defender RBAC

    Use Microsoft Defender unified role-based access control (RBAC) to grant users and groups the agentic code security permissions they need.required to run scans, upload results, and review or manage findings. In this step, you create a custom, feature-scoped role in Microsoft Defender for these specific capabilities, and then assign the role to the users who need access.

    1. Sign in to the Microsoft Defender portal.

    2. In the navigation pane, select System > Permissions.

    3. Under Microsoft Defender XDR, select Roles > Create custom role.

    4. On the Basics tab, enter a role name and description.

    5. On Choose permissions, expand Agentic code security.

    6. Under AI Scan Security, set the permission levels you need:need (for more information, see Security posture – AI code scan:

      • To allow users to run AI scans, select Run scan (Manage). — required to trigger on-demand or CLI scans.
      • To allow usersUpload results (Manage) — required to upload AICLI scan results to Defender, select Defender.
      • UploadScan results (Manage). — required to triage, dismiss, or otherwise manage findings.
      • To allow users to read scan results, select Scan results (Read).
      • — required to view findings in the Defender portal and the initiative. This permission does not grant access to the Defender portal. To allow usersenable portal access, assign additional permissions, such as Exposure Management (Read). These permissions may also provide access to manage scan results, select Scan results (Manage).other data within the assigned scope, beyond codename MDASH data.

      For more information, see Security posture – AI code scan.

    7. Review the permissions, and select Apply.

    8. Select Next to go to Assign users and data sources. Assign the users who should receive this role.

    9. Select Add assignment, and configure users, groups, and data sources.

    10. Under Data sources, keep both Microsoft Defender for Cloud and Microsoft Security Exposure Management selected.

    11. Select Add, review the assignments, and select Next.

    12. Review the role details,details and select Submit.

    For more information, see Create custom roles with Microsoft Defender unified RBAC.

    Entry points

    Start the onboarding flow from either of these locations in the Microsoft Defender portal:Microsoft Defender portal:

    • Exposure Management > Overview: Select Agentic code security.
    • Exposure Management > Initiatives: Select the Codename MDASH - Agentic code scanner initiative.
    1. Review the terms and conditions in the onboarding flow.
    2. Select the checkbox to confirm acceptance.
    3. You must accept the terms and conditions before you can select Save.

    Step 2: Connect a Microsoft Foundry resource

    Provide the required details to connect your Microsoft Foundry resource and validate the connection.

    1. Enter the Project endpoint (for example: https://your-foundry.azure.com) and API key.
    2. Select Validate to verify the connection.
    3. Select Save to finish onboarding.
  • Choose an authentication method: Keyless (recommended) or API key. For details, see Authentication methods.

  • Select Validate to verify the connection.

  • Select Save to finish onboarding.

  • Note: You must successfully validate the resource before you can select Save.

    Step 4: Set up AI scanning

    Remote scan (recommended)

    Create a GitHub connector

    Create a GitHub or Azure DevOps connector to connect your SCM organization and trigger on-demand scans through the Defender portal without installing anything locally.

    To create an SCM connector, you need access to the Microsoft Defender portal with permission to manage connectors, and you must have either the Global Administrator or Security Administrator role in Microsoft Entra ID. You must also have the Organization Owner role in the GitHub organization or Project Collection Administrator role in the Azure DevOps organization that you want to connect.

    1. Create a GitHub connector to connect your GitHub organization and trigger on-demand scans through the Defender portal without installing anything locally.

      To create a GitHub connector, you need access to the Microsoft Defender portal with permission to manage connectors, and you must have either the Global Administratoror Security Administrator role in Microsoft Entra ID. You must also have the Organization Owner role in the GitHub organization that you want to connect.

      1. Create a GitHub connectorCreate an Azure DevOps connector to connect your GitHubAzure DevOps organization.
      2. Trigger an on-demand agentic scan for any onboarded repository.

      Defender CLI

      To onboard agentic code security with Defender CLI, you need the Global Administrator or Security Administrator role in Microsoft Entra ID.

      1. Defender CLI setup
      2. Install and run Defender CLI.

      Step 5: Review security findings

      After scans run, view security findings in the Microsoft Defender portal.

      For step-by-step instructions,details, see Defender CLI setup and Install and run Defender CLI.

      Step 5: Review recommendations

      After scans run, view findings in the Microsoft Defender portal.

      For details, see Codename MDASH - Agentic code scanner initiativeCodename MDASH - Agentic code scanner initiative.

      Related content