Microsoft introduced MDASH, its agentic security scanning harness, to reduce noisy vulnerability alerts by prioritizing real, exploitable risks. At Build 2026, MDASH moved from private preview to an expanded enterprise security platform, folding MDASH into Defender, GitHub Code Security, Agent 365, and Purview to enable cross-tool context and remediation workflows. Aleš Holeček emphasized that AI vulnerability discovery has shifted from research curiosity to production-grade defense, with the durable advantage lying in the agentic system around the model rather than any single model. Microsoft described a model-agnostic approach that mixes heavy-reasoning models with lower-cost ones to balance speed and cost while enabling model swaps as needed. In CyberGym benchmarks, MDASH improved to 96.55% from 88.45% previously. The expanded preview integrates Defender for runtime context and enriches code vulnerabilities with production signals like internet exposure and data sensitivity for prioritization. Developers can use GitHub Copilot autofix and the Copilot cloud agent to generate, assign, and validate fixes, advancing remediation earlier in the lifecycle. PwC and Accenture executives praised the potential to simplify SecOps and increase resilience. Microsoft frames the rollout as part of securing the AI development lifecycle and fostering trust across innovation and safety.
MDASH is now part of a broader enterprise security control plane, with Defender integration and cross-tool remediation workflows across Defender, GitHub Code Security, Agent 365, and Purview.
Unchanged: The core concept of prioritizing actionable vulnerabilities through agentic AI triage and the use of model-based reasoning remains central; the emphasis on trust and production-grade defenses persists.
Positive about moving toward proactive, integrated AI-based security, with cautious note on integration complexity and trust requirements.
Demonstrates tangible enterprise AI deployment for security workflows and vulnerability triage.
Integrated, prioritized defense across development and operations enhances security posture.
Defender and Purview integration strengthens cloud-based security governance.
Tight integration into development workflows reduces cycle time for remediation.
MDASH, Copilot autofix, and cloud agents constitute a cohesive security tooling suite.
Enterprise security platform expansion signals broader market adoption and potential ROI.
Driver of MDASH rollout and security platform strategy
Primary product discussed in security triage expansion
Integral to the expanded security control plane
Key component of cross-tool remediation
Data governance integration in security workflow
Shifting from reactive scanning to agent-based triage across a security control plane can reduce alert fatigue, accelerate remediation, and improve governance for AI-enabled software. The model-agnostic, production-oriented approach is designed to scale with diverse codebases and deployment contexts, potentially reshaping SecOps practices and vendor lock-in dynamics.
Triage is streamlined and remediation can be automated via Copilot autofix, reducing toil.
A unified security plane promises stronger security posture across the software lifecycle.
Contextual signals across tools improve prioritization and response efficiency.
Deeper integration strengthens the value proposition of Defender, GitHub, and Purview.
Enterprise-wide relevance across regions and industries.
Reliance on AI models requires robust safeguards and monitoring.
Enrichment of vulnerabilities with production signals involves data handling concerns.
Positive reception from industry leaders; risk arises if integration underdelivers.
Cross-tool integration at scale can face technical and organizational hurdles.
Dependence on integrated Microsoft security stack could raise deployment complexity.
Product roadmap focuses on enterprise security; minimal geopolitical friction.
No explicit regulatory changes tied to MDASH rollout.
Primarily software tooling with established vendor ecosystem.
Automation may reduce some toil but creates demand for security engineers and architects.
Acknowledges trust and safety as core principles, mitigating liability concerns.
Industry validation and endorsement of MDASH approach