Control AI Apps on Managed Devices
Prevents installation and execution of unsanctioned AI apps and local AI agents on managed devices using Intune app control policies and Microsoft 365 admin center shadow AI governance across Windows, iOS/iPadOS, Android, and macOS.
Core capabilities
-
Deploy device restriction profiles, allow/block lists, and App Control for Business policies to prevent unsanctioned AI apps from being installed or executed on managed devices
Supporting capabilities 2
-
Build a centralized inventory of local AI agents and MCP servers running across managed Windows and macOS devices, with exposure mapping and KQL hunting to identify what needs to be governed or blocked
-
Detect and block unmanaged AI agents such as local MCP servers and agentic CLIs on managed Windows devices by pushing Intune enforcement policies from the Microsoft 365 admin center