Microsoft Security Exposure Management
Vulnerabilities and exposure

Set up Microsoft Foundry for Codename MDASH - Agentic code scanner integration

In brief

The MDASH integration documentation now describes Keyless authentication as recommended, API-key authentication, required permissions, onboarding values, and updated steps for creating a Foundry project.

What Defender admins need to know

Administrators should review the revised prerequisites and authentication setup before onboarding MDASH, including permissions, resource IDs, endpoints, and credentials.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Connect Microsoft Foundry (private preview)(Preview)

Create an Microsoft Foundry resource to use as part of the agentic code security setup. Microsoft Foundry hosts and serves the AI models that codename MDASH uses during agentic scans.

Prerequisites

Create an Microsoft Foundry resource

Before you start,To create a Microsoft Foundry project, follow these steps.

  1. Sign in to Microsoft Foundry.
  2. In the navigation bar, make sure thatthe New Foundry toggle is on.
  3. In the dropdown, select Create a new project.
  4. Enter a Project name, such as my-foundry-project.
  5. Select Advanced options to configure the resource group and location.
    • Resource group: Create a new resource group or select an existing one. If you create a new resource group, you can createmore easily manage the project and all its resources together.
    • Location: Select the region where the project will be created.
  6. Select Create project.

Wait for the project to be created. When the project overview page appears, your project is ready.

Authentication methods

During MDASH onboarding in the targetMicrosoft Defender portal, you're asked to choose how MDASH authenticates to your Microsoft Foundry resource. Use this section before you start onboarding to decide which authentication method to use and to prepare the required values, permissions, and setup steps.

MDASH supports two authentication methods for connecting to your Microsoft Foundry resource: Keyless (recommended) and API key.

Keyless (recommended)

Keyless authentication is recommended for most customers. It uses managed identity and RBAC for access control, avoids storing secrets in Defender, and removes API key rotation from the connection lifecycle.

To use Keyless authentication, run the one-time onboarding script. The minimum permissions required to run the script are:

  • Contributor on the managed identity's resource group, to create the managed identity and federated identity credential.

  • Role Based Access Control Administrator on the Foundry account, to assign the Foundry User role.

Alternatively, if the Foundry account and managed identity are in the same resource group, Owner on that resource group is sufficient. If they are in different resource groups, Owner is required on both resource groups.

As part of running the script, you'll need to provide your Foundry resource ID. You can find it in the Azure subscriptionportal under your Foundry resource (Overview → JSON View → Resource ID

After the script completes, copy the generated values required by the Defender onboarding flow: Tenant ID and resource group.Managed Identity Client ID.

API key

API key authentication uses an API key copied from the Microsoft Foundry portal. You are responsible for storing, rotating, and revoking the API key according to your organization's security requirements.

Copy the required values

Copy the values that MDASH needs to connect to your Foundry project. The values you need depend on the authentication method you choose during MDASH onboarding in the Microsoft Defender portal.

Project endpoint

Locate Project Endpoint, and then copy it. The Project endpoint is required for both authentication methods.

Keyless (recommended)

If you plan to use Keyless authentication, run the one-time setup script described in Authentication methods, and copy the generated values requested by the onboarding flow: Tenant ID and Managed Identity Client ID.

API key

If you plan to use API key authentication, locate API Key, and then copy it.

From the Foundry project's home page, copy the values that the service needs to connect to your Foundry project.

  1. Locate Project Endpoint, and then copy it.
  2. Locate API Key, and then copy it.

Deploy the required models

Deploy the models required for the agentic code security integration.

  1. Go to Build from the Azure portal.upper navigation menu.
  2. Search forFrom the menu, select Microsoft FoundryModels, and then underor Use with Foundry, select FoundryDeployments.
  3. Select Create, and then create a new Microsoft Foundry resource.
  4. Choose the subscription and resource group.
  5. Enter the resource name, region, and default project name.Deployments tab.
  6. Select Review + create, and then select CreateDeploy a base model.
  7. After deployment finishes, select Go to resource.

Open your Foundry project

Open the project that you created so you canChoose and deploy the requiredfollowing models and copywith default or custom settings:

  • GPT-General profile: Deploy all three models:

    • gpt-5.4
    • gpt-5.3-codex
    • gpt-5.4-mini

    Deploy each model only once.

  • MAI-Augmented profile (Preview): To use this profile, deploy the onboarding values.three models listed previously and:

    1. Go to the Microsoft Foundry resource that you created.
    2. Open the project, or select Go to Foundry portal to open the Microsoft Foundry experience.

      MAI-Cyber-1-Flash

Configure the TPM rate limit

  1. Repeat these steps for each deployed model.

Configure content filtering

Configure a content filter to ensure the deployed models can operate without restrictions. Codename MDASH sends security content that default filters might misclassify as harmful and block, causing missed findings. Minimum filter thresholds are required for reliable scans.

Prerequisites

  • A Microsoft Foundry resource is created, and three model deployments are completed.
  • The same setup applies to the new MAI-Cyber-1-Flash model, which is part of the MAI-Augmented profile (Preview).

Create a content filter

To create a content filter, follow these steps:

  1. Turn off the New Foundry toggle.
  2. Navigate to Guardrails + Controls > Content Filters, and select Create a content filter.

Allow Codename MDASH to access your Microsoft Foundry resource

Codename MDASH needs to access your Microsoft Foundry endpoint to validate credentials and run agentic scans. When your Foundry resource networking is set to Selected networks and private endpoints, all inbound traffic is blocked by default, including requests from MDASH. Without allowing the required IP addresses, validation of the Foundry resource during MDASH onboarding will fail.

To allow Codename MDASH to access your Microsoft Foundry resource, you should run script to configure access:

Run a script

Run the following script to automatically add the required IP addresses to your Foundry resource.

"172.175.149.64/26"

ScannerService. Single hosts for Cognitive Services require bare IPs, not /32.

"104.211.200.71" "104.211.201.192" "104.211.201.50" "104.211.201.51" "104.46.233.33" "104.46.233.67" "104.46.233.87" "130.33.185.234" "130.33.202.119" "130.33.219.176" "131.145.18.141" "134.112.1.46" "134.112.1.52" "134.112.1.53" "134.112.167.139" "134.112.167.67" "134.112.4.189" "135.149.44.23" "135.235.144.150" "135.235.144.187" "135.235.146.170" "145.133.61.218" "172.165.59.10" "172.194.141.170" "172.194.217.145" "172.215.236.113" "20.109.129.121" "20.11.91.116" "20.11.95.165" "20.162.184.22" "20.162.24.144" "20.162.24.92" "20.162.24.93" "20.162.65.100" "20.162.91.186" "20.165.140.244" "20.165.151.176" "20.165.151.56" "20.165.174.253" "20.165.205.170" "20.165.234.157" "20.165.236.243" "20.165.236.96" "20.165.237.202" "20.165.238.190" "20.167.12.148" "20.167.37.165" "20.167.37.233" "20.167.74.246" "20.167.93.128" "20.174.110.86" "20.174.145.41" "20.174.210.75" "20.174.40.24" "20.174.40.25" "20.174.40.30" "20.174.40.31" "20.174.45.75" "20.174.52.243" "20.174.56.196" "20.189.201.102" "20.190.97.30" "20.199.156.152" "20.199.156.153" "20.199.242.246" "20.199.243.150" "20.199.243.168" "20.199.243.221" "20.204.190.14" "20.204.220.227" "20.204.223.221" "20.208.161.207" "20.208.174.42" "20.208.174.48" "20.208.174.51" "20.208.195.174" "20.208.208.109" "20.208.219.170" "20.208.219.196" "20.208.219.212" "20.208.219.222" "20.208.71.207" "20.210.129.166" "20.210.74.194" "20.210.75.93" "20.211.143.180" "20.215.88.233" "20.215.92.253" "20.215.97.124" "20.215.97.127" "20.216.114.95" "20.216.73.20" "20.216.73.42" "20.216.83.177" "20.216.83.184" "20.216.83.209" "20.216.83.215" "20.227.117.88" "20.227.13.139" "20.227.80.166" "20.235.160.115" "20.235.160.129" "20.235.161.145" "20.235.161.49" "20.235.28.183" "20.235.31.237" "20.250.52.249" "20.250.82.4" "20.250.94.217" "20.254.10.208" "20.254.129.190" "20.26.65.37" "20.26.76.115" "20.26.97.68" "20.27.1.12" "20.27.145.27" "20.29.168.222" "20.3.68.203" "20.41.237.152" "20.41.238.3" "20.41.248.161" "20.41.248.217" "20.42.238.134" "20.42.238.143" "20.42.238.250" "20.45.68.1" "20.45.69.146" "20.45.72.33" "20.45.72.62" "20.49.172.249" "20.63.209.151" "20.63.209.208" "20.63.218.158" "20.63.218.90" "20.64.140.167" "20.68.110.201" "20.68.110.82" "20.69.29.166" "20.69.31.238" "20.69.65.49" "20.69.78.214" "20.70.106.32" "20.70.113.167" "20.70.113.215" "20.70.120.212" "20.70.67.48" "20.70.81.135" "20.70.81.159" "20.70.88.61" "20.70.90.144" "20.70.97.185" "20.70.98.111" "20.78.145.97" "20.78.154.200" "20.78.154.213" "20.78.25.32" "20.80.128.199" "20.89.225.114" "20.89.240.224" "20.89.248.208" "20.90.207.64" "20.90.229.224" "20.90.24.42" "20.90.28.144" "20.99.137.27" "23.101.236.20" "4.149.139.101" "4.149.231.71" "4.158.11.9" "4.165.158.55" "4.165.158.94" "4.165.225.95" "4.165.60.196" "4.166.213.157" "4.166.65.172" "4.187.235.192" "4.188.118.37" "4.188.118.72" "4.190.16.208" "4.195.101.238" "4.198.0.78" "4.224.155.228" "4.224.155.241" "4.224.191.134" "4.224.191.229" "4.224.191.56" "4.225.109.30" "4.225.196.217" "4.225.53.132" "4.225.55.83" "4.225.77.29" "4.226.115.190" "4.226.20.93" "4.226.22.143" "4.226.22.220" "4.226.46.240" "4.237.164.83" "4.242.88.151" "4.246.21.140" "4.247.232.121" "4.250.139.38" "4.254.89.110" "4.254.89.39" "4.255.166.236" "40.74.64.247" "40.81.155.253" "48.200.1.235" "48.200.114.83" "48.218.193.214" "48.218.239.115" "51.104.35.80" "51.104.58.106" "51.104.58.107" "51.107.172.134" "51.107.172.254" "51.107.225.181" "51.107.235.167" "51.107.236.148" "51.107.236.31" "51.11.18.122" "51.141.124.15" "51.141.124.22" "51.142.161.229" "52.140.53.223" "52.140.54.240" "52.161.49.73" "52.161.50.212" "52.185.180.52" "52.185.181.164" "74.161.66.49" "74.162.141.79" "74.162.141.97" "74.162.141.99" "74.162.165.123" "74.162.165.169" "74.162.165.209" "74.176.139.232" "74.176.169.132" "74.241.164.71" "74.243.11.239" "74.243.12.147" "74.243.13.0" "74.243.13.4" "74.243.13.9" "74.248.72.99" "74.248.74.226" "74.248.75.255" "74.248.76.190" "85.210.182.96" "9.223.145.21" "9.223.149.144" "9.223.169.160" "9.223.210.9" "98.70.233.44" )

SUBSCRIPTION=$(az account show --query id -o tsv) ./foundry-ip-rules.sh


## Defender portal onboarding

Complete Defender portal onboarding from the getting started page. For more information, see [Step 3: Defender portal onboarding](ai-code-security-onboarding.md#step-3-defender-portal-onboarding).
To replace a connected Foundry with a different one, or to remove the connection, you can disconnect at any time.

1. Go to the **Initiative** and select **Settings** (top-right).

2. Select **Disconnect** next to the connected Foundry resource, then confirm by selecting **Disconnect**.

Once disconnected, you can leave it as is or reconnect at any time to the same Foundry or to a different one.

For Keyless authentication, disconnecting doesn't remove the managed identity, federated identity credential, or RBAC role assignment created for the connection. When you disconnect the Foundry resource in the portal, the confirmation dialog provides an optional cleanup script that removes these resources—select Copy script to run it. Running it is optional - run it if your organization requires full cleanup.

For API key authentication, disconnecting doesn't delete or rotate the API key in Foundry. Revoke or rotate the key separately if it is no longer needed.

Switch authentication method

You can switch the authentication method for a connected Foundry resource to be Keyless at any time.

  1. Go to the Initiative and select Settings.

  2. Next to the connected Foundry resource, select Switch method to Keyless. For details about both authentication methods, setup steps, and required permissions, see Authentication methods.

  3. Trigger an on-demand agentic scan

    Select Validate to verify the new authentication method.

  4. View results in the initiative

    Select Save to apply the change.

Until the new authentication method is validated and saved, MDASH continues to use the existing authentication method for scans.

Related content