Microsoft is putting an army of AI agents to work hunting software vulnerabilities, and some of its government partners are getting access.
The company announced Tuesday that its multi-model agentic security scanner, codename MDASH, has been deployed in Microsoft Azure Government, with preview access available to select US government customers and authorized partners. According to Microsoft, the system uses more than 100 specialized AI agents to find, validate, and prioritize exploitable vulnerabilities in source code.
For Microsoft partners serving government agencies and other highly regulated organizations, the rollout could create opportunities beyond simply selling another security product. Assessments, remediation, cloud security implementation, compliance, and ongoing managed services could all become part of the conversation as AI-assisted vulnerability discovery moves into production environments.
MDASH uses more than 100 AI agents to hunt vulnerabilities
Microsoft says most traditional security scanning tools rely on known patterns to identify potential weaknesses. MDASH takes a different approach by using AI agents to reason through how code behaves and determine whether an identified weakness can actually be exploited.
More than 100 specialized agents examine code, with different agents focusing on specific classes of vulnerabilities. Other agents then evaluate findings and debate whether an issue is reachable and dangerous, while the system merges duplicate results before sending a prioritized list to security teams, according to Microsoft’s MDASH announcement.
Microsoft reports that MDASH scored 96.55 on the public CyberGym benchmark, which is based on real-world vulnerabilities. The company has cautioned, however, that a fixed benchmark cannot fully capture the ambiguity and complexity of finding vulnerabilities in real-world software.
In an earlier security update, Microsoft said engineering teams were already using MDASH across Windows, Azure, and identity systems as part of real security workflows rather than isolated testing.
Microsoft also says validated MDASH findings can flow into Defender workflows, GitHub, and Azure DevOps for prioritization, validation, and remediation. Separately, at Build 2026, Microsoft announced a native integration between Microsoft Defender and GitHub Code Security that brings runtime context into development and security workflows, helping teams prioritize and address risks.
Azure Government brings MDASH into a regulated environment
Security scanning becomes more complicated when the code being analyzed supports government missions or contains highly sensitive information.
Microsoft says MDASH operates within Azure Government and uses models available through the FedRAMP High-authorized Microsoft Foundry service. In its Azure Government announcement, the company said this approach allows an agency’s source code and what the system learns about it to remain within a boundary already approved for handling that data.
Partners aren’t entirely new to MDASH. At Build 2026, Microsoft said a select group of security partners and Microsoft Intelligent Security Association members were participating in the MDASH preview to help shape the technology and accelerate agentic AI vulnerability discovery.
That involvement fits into Microsoft’s broader push to get its partner ecosystem building services around AI and security.
Channel Insider previously examined Microsoft’s AI partner push, in which the company encourages partners to build services around Copilot, security, and agent-based AI.
In a separate Channel Insider interview, Logicalis discussed the growing role partners play in moving customers from experimentation toward enterprise AI deployments, including the governance and operational work required to put those systems into production.
What MDASH could mean for Microsoft partners
For authorized partners with public-sector practices, MDASH could open conversations around vulnerability assessment, remediation, DevSecOps integration, compliance, and managed security services.
Microsoft has not announced a dedicated MDASH partner services program. But its decision to include authorized partners in the Azure Government preview, combined with the security partners already helping shape MDASH, gives the channel an early role as the technology moves further into production environments.
The opportunity may extend beyond deploying the technology itself. Customers could need help determining which applications to scan first, interpreting and prioritizing findings, integrating results into existing security workflows, and turning identified vulnerabilities into remediation plans.
That services layer matters. Channel Insider has previously explored demand for Microsoft security services that extend beyond license resale into assessment, deployment, governance, and ongoing optimization.
MDASH remains in preview for select government customers and authorized partners, so this is not yet a broad channel offering. But Microsoft’s direction is becoming clearer. As increasingly sophisticated AI security tools enter regulated environments, partners that can translate those capabilities into measurable security outcomes could have a new service opportunity to build around them.
Related reading: For more on Microsoft’s expanding AI security strategy, read how Project Perception and MAI-Cyber-1-Flash are bringing agentic vulnerability discovery and risk prioritization to enterprise security teams.





