What you need to know
Does Defender for Cloud agentless code scanning evaluate every proposed change before a build proceeds?
Potentially affected
Supported Azure DevOps and GitHub connectors using Defender for Cloud agentless code scanning, currently in preview.
DSE recommendation
Document scheduled repository coverage separately from the checks that actually decide whether a proposed change may merge or release.
Source facts
Defender for Cloud’s agentless code scanning is in preview. The documented process discovers repositories initially and every eight hours, but retrieves code from each repository’s default branch initially and daily. Its comparison with in-pipeline scanning explicitly says agentless scanning cannot break builds. Finding a repository through the connector is therefore different from evaluating each proposed change during its build. Microsoft Learn.
Applicability
Review supported Azure DevOps or GitHub connectors, current regional availability, enabled scanners, and the actual repository scope. Identify the default branch and the branch or revision involved in the release decision. This brief does not claim that every language, artifact, or repository is scanned by every tool.
DSE recommendation
Document scheduled repository coverage separately from the checks that actually decide whether a proposed change may merge or release. Have security and development owners name the evidence required for each decision. Preserve an explicit gap when a proposed revision lacks the intended pre-release check rather than treating a connector recommendation as an automatic build gate.
Verification
Compare the repository’s observed discovery and scan records with its default branch and recent changes. Then inspect the pipeline or merge controls independently to establish which checks can prevent progression. Use a harmless test change in an approved repository to validate the intended workflow. Record the evaluated revision and decision point without claiming that a later scheduled result represents an earlier pull-request assessment.
Official references
Microsoft Learn: Configure agentless code scanning (Preview). Source reviewed September 9, 2026.
Review the official source
Configure agentless code scanning (Preview) - Microsoft Defender for Cloud | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE