# Separate scheduled default-branch scans from a pull-request release gate

> Does Defender for Cloud agentless code scanning evaluate every proposed change before a build proceeds?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-411-separate-scheduled-default-branch-scans-from-a-pull-request-release-gate/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:05+00:00
- Modified: 2026-09-10T02:04:57+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Briefing
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does Defender for Cloud agentless code scanning evaluate every proposed change before a build proceeds?

## Potentially affected

Supported Azure DevOps and GitHub connectors using Defender for Cloud agentless code scanning, currently in preview.

## DSE recommendation

Document scheduled repository coverage separately from the checks that actually decide whether a proposed change may merge or release.

## Article

## Source facts

Defender for Cloud’s agentless code scanning is in preview. The documented process discovers repositories initially and every eight hours, but retrieves code from each repository’s default branch initially and daily. Its comparison with in-pipeline scanning explicitly says agentless scanning cannot break builds. Finding a repository through the connector is therefore different from evaluating each proposed change during its build. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/defender-for-cloud/agentless-code-scanning).

## Applicability

Review supported Azure DevOps or GitHub connectors, current regional availability, enabled scanners, and the actual repository scope. Identify the default branch and the branch or revision involved in the release decision. This brief does not claim that every language, artifact, or repository is scanned by every tool.

## DSE recommendation

Document scheduled repository coverage separately from the checks that actually decide whether a proposed change may merge or release. Have security and development owners name the evidence required for each decision. Preserve an explicit gap when a proposed revision lacks the intended pre-release check rather than treating a connector recommendation as an automatic build gate.

## Verification

Compare the repository’s observed discovery and scan records with its default branch and recent changes. Then inspect the pipeline or merge controls independently to establish which checks can prevent progression. Use a harmless test change in an approved repository to validate the intended workflow. Record the evaluated revision and decision point without claiming that a later scheduled result represents an earlier pull-request assessment.

## Official references

[Microsoft Learn: Configure agentless code scanning (Preview)](https://learn.microsoft.com/en-us/azure/defender-for-cloud/agentless-code-scanning). Source reviewed September 9, 2026.

## Primary reference

- Name: Configure agentless code scanning (Preview) - Microsoft Defender for Cloud | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/defender-for-cloud/agentless-code-scanning
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate scheduled default-branch scans from a pull-request release gate,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-411-separate-scheduled-default-branch-scans-from-a-pull-request-release-gate/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
