Microsoft Deploys Agentic AI Vulnerability Scanner to Azure Government
Microsoft has deployed codename MDASH, an agentic AI-powered scanning system built to identify and validate software vulnerabilities, to Microsoft Azure Government. Select U.S. government agencies and authorized partners now have preview access to the tool, which Microsoft says can find software weaknesses across complex supply chains before adversaries exploit them.
The deployment comes as threat actors increasingly use AI to search for gaps in mission-critical systems. Douglas Phillips, president and chief technology officer of Microsoft Specialized Clouds, wrote in a blog post Tuesday that the tool is designed to help defenders stay ahead of that shift.
How Codename MDASH Works
Codename MDASH functions as an agentic code scanner that reads and analyzes software the way a human security researcher would, tracing how information moves through a program to determine whether a flaw is genuinely exploitable. The system uses more than 100 specialized AI agents spanning multiple models, each trained to identify a distinct category of vulnerability.
A second set of agents then reviews those findings, weighing evidence for and against whether each suspected flaw is reachable and poses a genuine risk. The system merges and deduplicates results, and where possible, demonstrates a vulnerability rather than simply flagging it. The output is a prioritized list for security teams to act on.
Microsoft said this multi-model, multi-agent design allows codename MDASH to reach a score of 96.55 on the CyberGym benchmark for real-world vulnerabilities. Phillips said the system's harness design lets it incorporate new AI models as they become available without requiring agencies to rebuild existing workflows. He added that Microsoft's MAI model family is intended to maximize cost-effectiveness, with the company's newest model expected to roughly halve the cost of an individual scan.
Operating Inside an Approved Boundary
Azure Government is an isolated cloud environment staffed by screened U.S. persons, built to meet compliance requirements for federal, national security, and state and local government customers. It holds FedRAMP High authorization and Department of War accreditation.
Codename MDASH runs within Azure Government as a feature of Microsoft Defender, drawing on models available through the FedRAMP High-authorized Microsoft Foundry service. That keeps an agency's source code and related analysis inside an already-approved boundary, a key requirement for federal security teams.
Phillips said Microsoft has used codename MDASH on its own software for several months. Government customers across national security and civilian agencies are now evaluating the tool. He described the defenders' advantage as the time between when a vulnerability is found and patched and when it might otherwise be discovered and exploited.
Broader AI Expansion on Azure Government
Codename MDASH is Microsoft's latest step in bringing AI-driven capabilities to federal agencies. In April 2025, Candice Ling, senior vice president of Microsoft's federal business, said AI would increasingly help defenders repel threats before they happen, rather than simply responding after an attack occurs.
Microsoft has since expanded AI capabilities on Azure Government through partnerships with Knox Systems, which helps commercial software companies get onto the platform faster, and SAS Viya, whose AI and analytics platform went live for federal customers.
Why this matters for government agencies
Federal security teams face a practical problem: software supply chains are large, and manual vulnerability review does not scale. A tool that reads code like a human researcher, validates whether a flaw is actually exploitable, and produces a prioritized list could reduce the window between discovery and remediation. Agencies evaluating codename MDASH should ask Microsoft for benchmark data on their own codebases, not just the published CyberGym score, and confirm how scan results integrate with existing Defender workflows before committing to deployment.
Your membership also unlocks: