Part of our it operations guide series

it-operations

Shadow AI Audit: Detect Unauthorized AI in Microsoft 365

Praveen11 min read
Minimal flat editorial illustration of enterprise security perimeter shield with unauthorized AI bot node highlighted in alert amber
On This Page (9 sections)
Workbench Security Audit

Auditing network telemetry or stopping background tracking? Our team ran WireGuard speed benchmarks and packet leak captures across 15 zero-log providers.

see the audited zero-log VPN comparison and packet tests

Direct Answer (How to Run a Shadow AI Audit in M365): To detect unsanctioned generative AI tools across your fleet without expensive third-party CASB add-ons: (1) open Microsoft Defender Portal (security.microsoft.com) > Cloud Apps > Cloud Discovery, (2) filter by App Category: Generative AI and sort by upload volume to identify data exfiltration risks, (3) review user-level activity via Microsoft Purview DLP and Defender for Endpoint network events, and (4) tag unsanctioned domains as Unsanctioned to enforce automated Edge browser blocks while redirecting staff to enterprise-protected Copilot.

In 2026, our IT operations and security team found that Shadow AI is the #1 data exfiltration risk facing corporate IT environments.

Well-meaning employees regularly paste confidential source code, customer support transcripts, or unreleased financial data into free consumer AI platforms to rewrite emails or generate summaries—unaware that consumer platforms often train public models on ingested inputs.

When IT leadership requests a Shadow AI audit, security vendors push expensive $50,000/year Cloud Access Security Broker (CASB) subscriptions. But if your organization uses Microsoft 365, you already possess the built-in telemetry tools to discover, audit, and block unauthorized AI web apps.

Here is our step-by-step workbench guide to running a complete Shadow AI audit using Microsoft Defender for Cloud Apps, Microsoft Edge for Business telemetry, Purview DLP, and PowerShell.



🛠️ 1. Architecture: The M365 Native Shadow AI Discovery Pipeline

Direct Answer: The Microsoft 365 native Shadow AI discovery pipeline relies on kernel-level network inspection in Microsoft Defender for Endpoint (MsMpEng.exe), streaming HTTPS domain queries to the Cloud Discovery dashboard without network proxy bottlenecks.

+-----------------------------------------------------------------------------------+
|      Microsoft 365 Native Shadow AI Discovery & Enforcement Architecture          |
+-----------------------------------------------------------------------------------+
| [User Endpoint Activity]                                                          |
|  - Edge / Chrome / Developer Terminal / Standalone Desktop AI Apps                |
|         │                                                                         |
|         ▼                                                                         |
| [Microsoft Defender for Endpoint: Network Protection Engine]                      |
|  - Inspects Outbound HTTPS Handshakes & DNS Resolutions                           |
|  - Logs Event ID 1125 (Network Inspection Block) / 1126 (Audited Connection)      |
|         │                                                                         |
|         ▼ (Encrypted Cloud Telemetry Stream)                                      |
| [Microsoft Defender Portal: security.microsoft.com]                              |
|  +─────────────────────────────────────────────────────────────────────────────+  |
|  | Cloud Apps > Cloud Discovery Dashboard                                      |  |
|  | - Filter Category: "Generative AI" (600+ Tracked AI Platforms)              |  |
|  | - Metrics: Total Traffic, Upload Volume (Exfiltration Risk), Unique Users   |  |
|  +──────────────────────────────────────┬──────────────────────────────────────+  |
|                                         │                                         |
|                                         ▼                                         |
| [Microsoft Purview AI Hub & DLP] ◄──────┴──────► [Defender Indicators & Filtering] |
|  - Classifies Sensitive Info Types (SIT)          - Tags App: "Unsanctioned"       |
|    (API Keys, Source Code, PII)                   - Pushes Block Rule to Edge/OS   |
|  - Enforces Data Loss Prevention                 - Redirects to Copilot Enterprise|
+-----------------------------------------------------------------------------------+

By inspecting network handshakes directly at the operating system layer, Microsoft Defender captures telemetry from remote workers, home Wi-Fi connections, and travel hotspots—completely eliminating the blind spots inherent to traditional corporate perimeter firewalls.


🔍 2. Step 1: Access Cloud Discovery in the M365 Defender Portal

Direct Answer: Access the native Cloud Discovery engine in Microsoft Defender to view automated categorizations for over 600 generative AI platforms without deploying third-party agent software.

  1. Navigate to the Microsoft Defender Portal (https://security.microsoft.com).
  2. In the left navigation menu, expand Cloud Apps and select Cloud Discovery.
  3. Click the Discovered Apps tab along the top navigation bar.
  4. Click Filter, select App Category, and check Generative AI.
  5. Click Apply.

Microsoft automatically tags traffic against a curated catalog of over 600 recognized AI services, including OpenAI, Anthropic, DeepSeek, Midjourney, Perplexity, and Hugging Face.


📊 3. Enterprise Shadow AI Risk & Data Exfiltration Matrix

Direct Answer: Evaluate your organization’s highest-traffic AI tools against our compliance matrix to measure data retention, training consent, and Microsoft risk ratings.

Sort the filtered Generative AI list by Upload Data Volume descending. On our enterprise workbench audits, sorting by upload volume immediately reveals which departments are pasting megabytes of internal files into untrusted services:

AI Platform & ServiceMicrosoft Risk Score (1-10)Public Model Training On Prompts?Enterprise Data Protection (EDP)?Recommended Policy Action
ChatGPT (Free / Plus Consumer)6 (Medium)Yes (Default opt-in)❌ NoneBlock via Defender Web Filtering
DeepSeek Web (chat.deepseek.com)4 (High Risk)Yes (Server-side retention)❌ NoneBlock via Network Protection
Claude.ai (Free Consumer Tier)6 (Medium)Yes (Unless opt-out requested)❌ NoneBlock; offer sanctioned alternative
Perplexity.ai (Free Consumer)6 (Medium)Yes (Enabled by default)❌ NoneBlock; enforce corporate search
Microsoft Copilot with EDP10 (Sanctioned)No (Strict zero-retention SLA)✅ Full HIPAA / GDPR / ISO complianceSanction & redirect all staff

Focus your initial security triage on any service with a Risk Score below 7 where employees have uploaded more than 100 MB of data over the past 30 days.


🛡️ 4. Step 2: Correlate Data Exfiltration with Microsoft Purview

Direct Answer: Leverage Microsoft Purview AI Hub and Data Loss Prevention (DLP) policies to detect whether pasted text contains credit card numbers, API credentials, or customer PII.

Knowing which app employees visited is only half the battle; security teams must verify what data left the perimeter.

  1. Open the Microsoft Purview Compliance Portal (https://purview.microsoft.com).
  2. Navigate to AI Hub (Preview) or Data Loss Prevention > Alerts.
  3. Review matches against Sensitive Information Types (SIT):
    • Search for triggers on Azure API Credentials, SQL Connection Strings, Credit Card Numbers, or Employee Identification Numbers.
  4. Review the user audit trail to determine if the prompt paste was a routine productivity task or an intentional exfiltration vector.

⚡ 5. Automated Developer Artifact: Audit-ShadowAIEndpoints.ps1

Direct Answer: Run our team’s automated PowerShell triage script to audit local workstation DNS caches, Defender Network Protection block events, and generate an exportable CSV risk summary.

To help IT administrators immediately verify whether unmanaged consumer AI endpoints are actively being queried on managed endpoints, our engineering team developed Audit-ShadowAIEndpoints.ps1. Run this non-destructive script in an elevated PowerShell session:

<#
.SYNOPSIS
    PraveenTechWorld - Endpoint Shadow AI Telemetry Audit Script
.DESCRIPTION
    Scans local DNS resolver cache, active TCP connections, and Microsoft
    Defender Network Protection event logs for unauthorized consumer AI usage.
#>

[CmdletBinding()]
param(
    [string]$ExportCsvPath = "$env:USERPROFILE\Desktop\ShadowAI_Endpoint_Audit.csv"
)

Write-Host "============================================================" -ForegroundColor Cyan
Write-Host "  PraveenTechWorld: M365 Endpoint Shadow AI Triage Tool     " -ForegroundColor Cyan
Write-Host "============================================================" -ForegroundColor Cyan

# 1. Target Consumer AI Domain Registry
$TargetAIEngines = @(
    @{ Name = "OpenAI ChatGPT"; Domain = "chatgpt.com"; Risk = "High" },
    @{ Name = "DeepSeek Web"; Domain = "deepseek.com"; Risk = "Critical" },
    @{ Name = "Anthropic Claude"; Domain = "claude.ai"; Risk = "High" },
    @{ Name = "Perplexity AI"; Domain = "perplexity.ai"; Risk = "Medium" },
    @{ Name = "Poe AI"; Domain = "poe.com"; Risk = "High" },
    @{ Name = "Midjourney Web"; Domain = "midjourney.com"; Risk = "Medium" }
)

# 2. Check DNS Cache for Recent Resolutions
Write-Host "`n[*] Inspecting Local DNS Resolver Cache..." -ForegroundColor Yellow
$dnsCache = Get-DnsClientCache
$findings = [System.Collections.Generic.List[PSCustomObject]]::new()

foreach ($ai in $TargetAIEngines) {
    $matchedRecord = $dnsCache | Where-Object { $_.Entry -like "*$($ai.Domain)*" }
    if ($matchedRecord) {
        Write-Host "  [!] ACTIVE DNS TRACE FOUND: $($ai.Name) ($($ai.Domain))" -ForegroundColor Red
        $findings.Add([PSCustomObject]@{
            Timestamp   = (Get-Date).ToString("yyyy-MM-dd HH:mm:ss")
            Type        = "DNS Cache Match"
            Service     = $ai.Name
            Domain      = $ai.Domain
            RiskLevel   = $ai.Risk
            Detail      = "Endpoint resolved domain within TTL cache window"
        })
    } else {
        Write-Host "  [+] Clean: No active cache for $($ai.Domain)" -ForegroundColor Green
    }
}

# 3. Check Microsoft Defender Network Protection Event Logs
Write-Host "`n[*] Auditing Microsoft Defender Network Inspection Events..." -ForegroundColor Yellow
$defenderLog = "Microsoft-Windows-Windows Defender/Operational"
if (Get-WinEvent -ListLog $defenderLog -ErrorAction SilentlyContinue) {
    # Event ID 1125: Network Protection Block | Event ID 1126: Network Protection Audit
    $events = Get-WinEvent -FilterHashtable @{
        LogName   = $defenderLog
        Id        = 1125, 1126
        StartTime = (Get-Date).AddDays(-7)
    } -ErrorAction SilentlyContinue

    if ($events) {
        Write-Host "  [+] Found $($events.Count) Network Protection security events in the last 7 days." -ForegroundColor DarkCyan
        foreach ($ev in $events) {
            $msg = $ev.Message
            foreach ($ai in $TargetAIEngines) {
                if ($msg -like "*$($ai.Domain)*") {
                    Write-Host "  [!] DEFENDER TRIGGER: Event $($ev.Id) on $($ai.Domain)" -ForegroundColor Red
                    $findings.Add([PSCustomObject]@{
                        Timestamp   = $ev.TimeCreated.ToString("yyyy-MM-dd HH:mm:ss")
                        Type        = "Defender Event $($ev.Id)"
                        Service     = $ai.Name
                        Domain      = $ai.Domain
                        RiskLevel   = $ai.Risk
                        Detail      = "Defender triggered Web Content filter block/audit"
                    })
                }
            }
        }
    } else {
        Write-Host "  [+] No Defender Network Protection blocks recorded in past 7 days." -ForegroundColor Green
    }
} else {
    Write-Host "  [-] Defender Operational event log not accessible" -ForegroundColor Gray
}

# 4. Export Findings to CSV
if ($findings.Count -gt 0) {
    Write-Host "`n[!] Risk Findings Identified: $($findings.Count) items recorded." -ForegroundColor Yellow
    $findings | Export-Csv -Path $ExportCsvPath -NoTypeInformation
    Write-Host "  [+] Exported forensic audit report to: $ExportCsvPath" -ForegroundColor Green
} else {
    Write-Host "`n[+] Zero Shadow AI traces detected on this host. System compliant." -ForegroundColor Green
}

Write-Host "`n============================================================" -ForegroundColor Cyan
Write-Host "  Audit Complete. Review exported CSV for security review. " -ForegroundColor Cyan
Write-Host "============================================================" -ForegroundColor Cyan

🚫 6. Step 3: Block Unsanctioned AI Endpoints via Web Content Filtering

Direct Answer: Tag high-risk generative AI tools as Unsanctioned in Defender for Cloud Apps to enforce automatic endpoint DNS and HTTPS blocks across your fleet.

Once you have documented consumer AI usage, configure Defender for Endpoint to block connection attempts:

  1. In the Defender Portal, return to Cloud Apps > Cloud Discovery > Discovered Apps.
  2. Select the checkbox next to ChatGPT, DeepSeek, or Claude.
  3. Click the Tag as Unsanctioned icon (circle with diagonal slash) at the top of the table.
  4. Microsoft Defender for Endpoint will sync this indicator to all enrolled Windows 10/11 devices within 15 minutes.
  5. When a user navigates to the domain in Microsoft Edge, Chrome, or Firefox, the Network Protection engine intercepts the socket and renders a corporate block banner.

🔀 7. Step 4: Route Employees to Sanctioned Enterprise Copilot

Direct Answer: Pair network blocks with educational browser redirects in Microsoft Edge for Business to prevent staff from moving Shadow AI activity to unmanaged personal devices.

Blocking tools without providing a viable alternative always backfires: employees will open mobile browsers or tether their personal smartphones to continue using AI.

  1. Open Microsoft Intune Admin Center (https://intune.microsoft.com).
  2. Navigate to Devices > Configuration > Manage Edge Policies.
  3. Configure the SmartScreen / Web Content Filter Block Page Redirect URL:
    • URL: https://m365.cloud.microsoft/chat (Enterprise Copilot).
  4. When a user navigates to chatgpt.com, Edge displays a clean prompt:

    “Access to consumer AI is restricted to protect corporate data. You have been redirected to Microsoft 365 Copilot, where Enterprise Data Protection is active.”

This turns security enforcement into a positive productivity booster rather than a frustrating roadblock.


📋 Shadow AI Audit Runbook Checklist

PhaseTool UsedObjectiveExecution Metric
1. DiscoveryDefender for Cloud AppsFilter Discovered Apps for Generative AIIdentify top 5 consumer AI web apps
2. Risk ScoredCloud DiscoverySort by Upload Data VolumeFlag users uploading over 100 MB
3. Content DLPMicrosoft Purview AI HubCheck Sensitive Info Types (SIT) matchesConfirm no API keys or credentials leaked
4. Host AuditAudit-ShadowAIEndpoints.ps1Scan local workstation DNS caches & event logsExport compliance verification CSV
5. EnforcementDefender for EndpointTag consumer apps as UnsanctionedPush zero-trust web content block
6. AdoptionMicrosoft Edge for BusinessRedirect blocked traffic to Enterprise CopilotZero productivity loss; 100% data privacy

For further IT infrastructure runbooks from our team’s workbench, explore our companion guides:

Cloud ComputeSponsored Developer Tool
Free PowerShell & Sysadmin Toolkit

Get Our Sysadmin & AI Runbooks Direct to Your Inbox

Join 2,500+ engineers receiving our weekly PowerShell automation scripts, root cause analyses, and hardware diagnostic playbooks.

Zero spam. Unsubscribe anytime in 1 click.

Frequently Asked Questions: Shadow AI Audit: Detect Unauthorized AI in Microsoft 365

What is Shadow AI in the workplace?
Shadow AI refers to employees independently using unauthorized or unsanctioned consumer AI tools (like free ChatGPT or Claude) to process company data without IT oversight or security approval.
Can Microsoft Defender track AI usage on non-company networks?
Yes. If an employee is using a managed corporate device, Microsoft Defender for Endpoint and Edge for Business telemetry will still log and block unauthorized AI web app traffic, even if they are connected to a home network or public Wi-Fi.
Why shouldn't IT just block all AI sites?
Blocking all AI sites without providing a sanctioned alternative usually drives Shadow IT underground. Employees will resort to using personal cell phones or mobile hotspots to access AI tools, completely bypassing your corporate telemetry and DLP protections.

Official Technical References

  1. Microsoft Learn: Discover and manage Shadow AI using Defender for Cloud Apps — Microsoft Learn
  2. Microsoft Learn: Microsoft Purview AI Data Security and Governance — Microsoft Learn
  3. Microsoft Learn: Configure Web Content Filtering in Defender for Endpoint — Microsoft Learn
Get Independent Tech Benchmarks First

Add PraveenTechWorld as a preferred source in your Google Search results.

Prefer on Google
P
Praveen

IT ops lead in India. I break Windows, Android and self-hosted AI stacks on my workbench, then write down what actually fixed them.

Explore more: Browse all it operations guides or check related articles below.