Microsoft Build 2026 adds security tools for code, agents, models

Microsoft used Build 2026 to announce new security features across code, agents, and models. The company said the updates are meant to give developers real-time guidance and give security teams more visibility across the development lifecycle.

Microsoft Build 2026 adds security tools for code, agents, models

Microsoft used Build 2026 to announce a set of security tools aimed at code, AI agents, and models, as it tries to close the gap between rapid development and security oversight. The company said the new capabilities are designed to give developers guidance in real time while giving security teams a consistent view across the full lifecycle, from code creation to runtime use.

The announcements come as Microsoft said AI is speeding up development while also creating new problems around insecure code, opaque models, data exposure, compliance, shadow AI, and tool sprawl. The company said those pressures have made security teams struggle to keep up with visibility and governance as developers move faster.

⚡ New to this?

This news is about Microsoft adding security features for AI code, AI agents, and AI models. A model is the AI system itself, while an agent is software that can take actions on its own, such as calling tools or accessing data. For non-experts, the main point is that Microsoft is trying to make AI development easier to control before risky code or sensitive data reaches production.

🦞 OpenClaw angle

If you run self-hosted agents, treat agent sprawl as a security problem, not just an ops issue. Keep a registry of every agent, its permissions, and the data sources it can reach, then block unknown local agents by default at the endpoint or container layer. Also add runtime checks for prompt data loss prevention and model artifact scanning in CI/CD so compromised models or sensitive prompts are caught before deployment.

For code security, Microsoft highlighted the Microsoft Security multi-model agentic scanning harness, codenamed MDASH. The company said MDASH is now in expanded preview for eligible organizations and includes integration with Microsoft Defender.

Microsoft described MDASH as an agentic security system that uses a pipeline of more than 100 specialized AI agents and an ensemble of models to discover, validate, and prove exploitability across codebases written in popular programming languages. The company said the system uses a configurable panel of models, ranging from heavier reasoning models to lower-cost models for high-volume tasks, in order to balance speed, recall, and cost.

Microsoft also said MDASH uses more than 100 trillion signals a day to focus on real risk rather than theoretical noise. The company said the system recently rose about 10% in less than three weeks to a CyberGym benchmark score of 96.55%.

Microsoft said it is also making its Defender and GitHub Code Security integration generally available. According to the company, the integration enriches vulnerabilities found in code with production context such as internet exposure and data sensitivity, so teams can prioritize what matters most.

Developers can then use GitHub Copilot Autofix and the GitHub Copilot cloud agent to generate, assign, and validate fixes. Microsoft said role-based access controls are included so that only authorized users can view and act on findings that involve real or potential vulnerabilities.

On agents, Microsoft said it is adding tools for developers who are shipping AI agents into production and for security teams that need to track what those agents can do. The company said the new Agent 365 SDK is now generally available and lets developers build controls such as observability, access controls, and compliance enforcement directly into agent workflows.

Microsoft also announced the Microsoft Execution Container, or MXC, SDK for Windows, which it said gives OS-level control over agent execution using isolation technologies such as process and session isolation. Windows 365 for Agents is now generally available, and Microsoft said it can run any agent in a fully isolated, policy-governed Cloud PC.

The company said native Windows integration with Agent 365 creates a common foundation for observability, security, and governance, with built-in Intune capabilities to set policies that control runtime behavior. These capabilities are now in early preview.

Microsoft said Agent 365 is also adding a registry that can surface unmanaged local agents discovered by Microsoft Defender, Microsoft Entra, and Microsoft Intune. The registry supports more than 20 types of local agents, including coding agents, AI desktop apps, and local and remote Model Context Protocol, or MCP, servers.

For data security, Microsoft said Purview controls will help prevent data exfiltration, support Data Security Posture Management risk discovery, and detect agentic risk in coding agents including Claude Code, GitHub Copilot, OpenAI Codex, and OpenClaw. The company said Purview Audit will also log agent activity for traceability.

Microsoft said Purview data risk signals are now embedded in the Foundry Control Plane, so developers can see data security issues in real time before deployment. The company also said runtime data loss prevention, or DLP, for agent prompts in Foundry is in preview with Agent 365. According to Microsoft, this can detect, block, and audit sensitive data before it is processed by an agent.

For models, Microsoft said Defender AI model scanning is now in preview. The company said the feature lets developers inspect platform-native or bring-your-own model artifacts and can detect and block potentially vulnerable or compromised models across registries, workspaces, and CI/CD pipelines before deployment.

Microsoft said the overall goal is to embed security into the platforms developers already use, including Microsoft Foundry, Copilot Studio, GitHub, and open-source frameworks. The company said that approach is intended to support secure development across the full lifecycle while also addressing shadow AI.

Source: Microsoft Security Blog ↗

More from Security News