SecOps SignalMicrosoft Security Operations Intelligence

Medium - Microsoft Security Exposure Management, Microsoft Defender portal, Codename MDASH agentic code scanner, Microsoft Defender CLI, Microsoft Foundry, Azure DevOps connector for Codename MDASH, Operational Technology platforms: Armis, Dragos, Forescout, Microsoft Defender for Cloud Apps - Microsoft primary source

Microsoft Security Exposure Management - Recent Feature Updates and Previews

Microsoft Security Exposure Management (MSEM) has introduced multiple new features and previews including keyless authentication for Foundry connections, agentic AI-based code scanning with Codename MDASH, new OT operational technology data connectors, updated critical asset and identity classifications, and an overview dashboard to consolidate exposure risk insights.

What changed

August 2026 updates enable keyless authentication using managed identities instead of API keys for Foundry connections; cancel scan option added to Microsoft Defender portal. Azure DevOps connector preview for remote on-demand agentic scans introduced. July 2026 releases feature MAI-Augmented scan profiles with specialized cyber AI models for enhanced code vulnerability detection available via Defender portal and CLI. Microsoft Security Exposure Management supports operational technology (OT) data connectors for Armis, Dragos, and Forescout to integrate OT asset data. June 2026 included new critical asset and identity classification rules for executive-sponsored AI agents, widespread local admins, and multiple SaaS application classifications (such as Microsoft Entra ID, Azure, 365 services). An updated overview dashboard is also previewed to aggregate exposure risks into actionable views.

Why it matters operationally

These enhancements improve vulnerability detection and prioritization capabilities, enable more secure authentication mechanisms, provide broader asset visibility (including OT environments), and improve monitoring and response for critical identities and assets. The addition of AI-augmented scanning could reduce false positives and increase detection accuracy in code repositories. The new classifications help better identify and manage high-risk identities and services to minimize exposure and prevent privilege escalations.

What the SOC should check

Validate affected Microsoft products, confirm whether controls or detections need tuning, and record any change-management or monitoring actions.

Recommended actions

  • Review and adopt keyless authentication for Microsoft Foundry connections to reduce secret management overhead.
  • Evaluate enabling Codename MDASH agentic code scanner preview and MAI-Augmented scan profiles to improve code security assessments.
  • Integrate OT data connectors if managing OT assets through Defender portal for unified visibility.
  • Ingest new predefined classifications into asset and identity risk analyses to enhance prioritization and reduce exposure.
  • Use the updated overview dashboard in preview to gain consolidated exposure insights and drive remediation efforts efficiently.

Source links

https://learn.microsoft.com/en-us/security-exposure-management/whats-new