Discover Shadow AI Usage
Builds visibility into which AI apps users are accessing, who is using them, and whether sensitive data is flowing into AI prompts — before taking any blocking action.
Core capabilities
-
Discover all AI apps in use across the organisation, score each by risk, and build a baseline of shadow AI activity
-
Surface user interactions with AI apps and detect whether sensitive information is flowing into prompts via DSPM for AI
Supporting capabilities 4
-
Discover generative AI apps, AI Model Provider APIs, and SaaS MCP servers from network traffic, with usage analytics, transferred data volumes, and Defender for Cloud Apps risk scores
-
Identify managed and shadow AI agents reaching the internet, attribute activity to the originating user, device, and process, and classify agents using Microsoft Entra Agent ID
-
Capture event-level GenAI prompt and remote MCP traffic telemetry, including destination URLs, MCP operations, payload content, and user attribution for deeper investigation
-
Identify users engaging in high-risk AI interactions by correlating browser, network, and M365 activity signals