Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
After activating the GitHub connector, the ability to trigger an on-demand agentic scan for onboarded repositories becomes available within up to one hour.
Prerequisites
- A GitHub connector created and activated. See Create a GitHub connector.
Step 1: Open Manage scans
- In the Microsoft Defender portal, go to Exposure management > Initiatives.
- Open the Codename MDASH - Agentic code scanner (preview) initiative, and then select Open initiative page.
- Select the Manage scans button (next to the Settings button).
Step 2: View the list of repositories
The side panel lists every repository discovered through the SCM connectors activated in your tenant.
For each repository, you can see:
- Repository name
- Repository size
- Organization name
- SCM type
- Scan status — last scan
- Tokens consumed in the last scan
The repository size and tokens consumed signals can help your security team predict the impact of a scan before running it.
Step 3: Select a repository and run a scan
- Select the repository you want to scan.
- Select Start scan.
- Confirm in the dialog that appears.
If your tenant already has 10 queued scans from the portal and the CLI combined, a warning appears. You can still submit the scan. Queued scans that don't start running within 72 hours of submission are automatically cleaned up, so some queued scans might not run.
A notification appears confirming the scan was started. The new scan appears in the Scans tab and progresses through its lifecycle.