WayToClawEarn
High impactMicrosoft Cloud Blog / Microsoft Security / Microsoft Learn

Microsoft Codename MDASH Reaches Azure Government: Can Agentic Scanning Become a Procureable Security Service?

Microsoft deployed Codename MDASH to Azure Government for preview access by selected US government customers and authorized partners. We separate the workflow, vendor claims, and practical service boundaries.

WayToClawEarn EditorialPublished Sep 8, 2026

Editorial review of public sources · AI-assisted drafting. How we work · Original source

Microsoft Codename MDASH Reaches Azure Government: Can Agentic Scanning Become a Procureable Security Service?

Bottom line

Microsoft announced on September 8, 2026 that Codename MDASH, its multi-model agentic security scanning system, is deployed in Azure Government and available in preview to selected US government customers and authorized partners. It is not a chatbot. It is a workflow in which specialized agents scan, challenge, deduplicate, validate, and help remediate software vulnerabilities.

The commercial signal is the productization of security work—not a promise that AI will find every vulnerability. Microsoft cites a 96.55 CyberGym score and expects the cost of an individual scan to fall by roughly half, but those are vendor-reported results or expectations, not independent measurements by WayToClawEarn.

What MDASH is becoming

MDASH is entering Azure Government as a Microsoft Defender capability, with preview access for selected US government customers and authorized partners. It orchestrates multiple models and agents to analyze source code and complex software environments, assess whether a suspected weakness is reachable and dangerous, and produce a deduplicated, prioritized set of findings with remediation guidance where possible.

Microsoft describes a workflow that includes:

  • multiple specialized agents analyzing the same codebase for different vulnerability classes;
  • a second group of agents arguing for and against each finding to reduce single-model judgment errors;
  • deduplication and prioritization, with evidence of exploitability where possible;
  • integration with Defender and engineering remediation workflows.

Why Azure Government matters

Microsoft says Azure Government is separated from commercial cloud, operated by screened US persons, and designed for requirements such as FedRAMP High. MDASH uses models available through Microsoft Foundry in that environment, with the goal of analyzing sensitive government code inside an existing compliance boundary.

That does not mean any team can use it immediately, and it does not mean a customer’s deployment is automatically certified for every use. The public announcement supports the narrower statement that MDASH is deployed in Azure Government and available to selected customers in preview.

How to read 96.55 and “half the cost

Microsoft says MDASH scored 96.55 on the public CyberGym benchmark and that a new model addition is expected to cut the cost of an individual scan roughly in half. Both claims need boundaries:

  1. The announcement does not provide the complete task mix, runtime configuration, false-positive rate, human-review cost, or end-to-end remediation success rate.
  2. A benchmark score does not imply the same result on your codebase.
  3. “Roughly half the cost” is a Microsoft product expectation, not a universal price promise; cloud boundary, code size, concurrency, model calls, and human review change total cost.

Any procurement or build-versus-buy evaluation should record codebase size and languages, scan time, confirmed findings, false positives, human confirmation time, post-fix test pass rate, model usage, and the total bill.

A monetization lesson: sell the verification loop, not an “AI finds bugs” slogan

If you build an AI-security service, a safer product wedge is findings verification and remediation coordination—not a promise to discover every vulnerability automatically. A minimal service package can:

  1. Start with an isolated test repository and fixed language/build versions.
  2. Require a security engineer to review findings and classify them as exploitable, unreachable, or insufficiently evidenced.
  3. Put fixes on a branch and run the customer’s existing tests before any production merge.
  4. Deliver the finding, evidence, false-positive rationale, patch diff, and rollback path.
  5. Track cost per code volume and confirmed findings across multiple cycles before expanding agent permissions.

There is no real customer billing or revenue record in this article, so it does not claim income, savings, or conversion results. Reproducible service value comes from the audit trail and remediation loop, not a single vendor benchmark number.

Sources and boundaries

This article labels product scope, the CyberGym score, and cost expectations as Microsoft information. WayToClawEarn did not independently benchmark MDASH and does not provide exploit instructions.

MDASHagentic securityAzure GovernmentcybersecurityAI agents

View source →

Disclaimer: this site shares educational insights only, for inspiration and reference. No outcome guarantee; external execution and decisions are your own responsibility.