Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Confirm you have everything in place before you begin, then follow the steps to connect your organization to agentic code security, codename MDASH, and start running scans on your code.
Prerequisites checklist
To complete this setup, you need:
- Global Administrator or Security Administrator role in Microsoft Entra ID to complete the agentic code security onboarding process in the Microsoft Defender portal.
- Authority to accept the codename MDASH terms and conditions on behalf of your organization during onboarding.
- An Azure subscription and resource group in which to create a dedicated Microsoft Foundry resource used exclusively for codename MDASH. For full details, see Connect Microsoft Foundry.
- Permission to deploy the models required. For list of models, see Deploy the required models.
- If the Foundry resource's networking is set to Selected networks and private endpoints, action is required to allow codename MDASH access. For more information, see Allow Codename MDASH to access your Microsoft Foundry resource.
- At least one of the following AI scanning paths:
- Option 1 — Remote scan (recommended). For full details, see either Create a GitHub connector or Create Azure DevOps connector.
- Option 2 — Defender CLI. For full details, see Defender CLI setup.
- If outbound traffic is restricted, allow the required domains. For more information, see Allow list.
- Access to the Microsoft Defender portal with permission to open Exposure Management and Initiatives.
- The Foundry project endpoint and API key from the Foundry setup step.
- Defender unified RBAC permissions assigned. For the required permissions and how to assign them, see Assign permissions to users using Defender RBAC.
Assign permissions to users using Defender RBAC
Use Microsoft Defender unified role-based access control (RBAC) to grant users the agentic code security permissions they need.
- Sign in to the Microsoft Defender portal.
- In the navigation pane, select System > Permissions.
- Under Microsoft Defender XDR, select Roles > Create custom role.
- On the Basics tab, enter a role name and description.
- On Choose permissions, expand Agentic code security.
- Under AI Scan Security, set the permission levels you need (for more information, see Security posture – AI code scan:
- Run scan (Manage) — required to trigger on-demand or CLI scans.
- Upload results (Manage) — required to upload CLI scan results to Defender.
- Scan results (Read) — required to view findings in the Defender portal and the initiative.
- Scan results (Manage) — required to triage, dismiss, or otherwise manage findings.
- Review the permissions, and select Apply.
- Select Next to go to Assign users and data sources. Assign the users who should receive this role.
- Select Add assignment, and configure users, groups, and data sources.
- Under Data sources, keep both Microsoft Defender for Cloud and Microsoft Security Exposure Management selected.
- Select Add, review the assignments, and select Next.
- Review the role details and select Submit.
For more information, see Create custom roles with Microsoft Defender unified RBAC.
Entry points
Start the onboarding flow from either of these locations in the Microsoft Defender portal:
- Exposure Management > Overview: Select Agentic code security.
- Exposure Management > Initiatives: Select the Codename MDASH - Agentic code scanner initiative.
Step 1: Accept terms and conditions
Review and accept the terms and conditions before you proceed.
- Review the terms and conditions in the onboarding flow.
- Select the checkbox to confirm acceptance.
- You must accept the terms and conditions before you can select Save.
Step 2: Connect a Microsoft Foundry resource
For step-by-step instructions on creating an Microsoft Foundry resource and deploying the required models, see Connect Microsoft Foundry.
Step 3: Defender portal onboarding
Provide the required details to connect your Microsoft Foundry resource and validate the connection.
- Enter the Project endpoint (for example:
https://your-foundry.azure.com) and API key. - Select Validate to verify the connection. You must successfully validate the resource before you can select Save.
- Select Save to finish onboarding.
Step 4: Set up AI scanning
Remote scan (recommended)
Note
You can create the GitHub or Azure DevOps connector either before or after codename MDASH onboarding.
Create a GitHub or Azure DevOps connector to connect your SCM organization and trigger on-demand scans through the Defender portal without installing anything locally.
To create an SCM connector, you need access to the Microsoft Defender portal with permission to manage connectors, and you must have either the Global Administrator or Security Administrator role in Microsoft Entra ID. You must also have the Organization Owner role in the GitHub organization or Project Collection Administrator role in the Azure DevOps organization that you want to connect.
- Create a GitHub connector to connect your GitHub organization or Create an Azure DevOps connector to connect your Azure DevOps organization.
- Trigger an on-demand agentic scan for any onboarded repository.
Defender CLI
To onboard agentic code security with Defender CLI, you need the Global Administrator or Security Administrator role in Microsoft Entra ID.
Step 5: Review security findings
After scans run, view security findings in the Microsoft Defender portal.
For details, see Codename MDASH - Agentic code scanner initiative.