it-operations
Shadow AI Audit: Detect Unauthorized AI in Microsoft 365

On This Page (9 sections)
Auditing network telemetry or stopping background tracking? Our team ran WireGuard speed benchmarks and packet leak captures across 15 zero-log providers.
see the audited zero-log VPN comparison and packet testsDirect Answer (How to Run a Shadow AI Audit in M365): To detect unsanctioned generative AI tools across your fleet without expensive third-party CASB add-ons: (1) open Microsoft Defender Portal (
security.microsoft.com) > Cloud Apps > Cloud Discovery, (2) filter by App Category: Generative AI and sort by upload volume to identify data exfiltration risks, (3) review user-level activity via Microsoft Purview DLP and Defender for Endpoint network events, and (4) tag unsanctioned domains as Unsanctioned to enforce automated Edge browser blocks while redirecting staff to enterprise-protected Copilot.
In 2026, our IT operations and security team found that Shadow AI is the #1 data exfiltration risk facing corporate IT environments.
Well-meaning employees regularly paste confidential source code, customer support transcripts, or unreleased financial data into free consumer AI platforms to rewrite emails or generate summaries—unaware that consumer platforms often train public models on ingested inputs.
When IT leadership requests a Shadow AI audit, security vendors push expensive $50,000/year Cloud Access Security Broker (CASB) subscriptions. But if your organization uses Microsoft 365, you already possess the built-in telemetry tools to discover, audit, and block unauthorized AI web apps.
Here is our step-by-step workbench guide to running a complete Shadow AI audit using Microsoft Defender for Cloud Apps, Microsoft Edge for Business telemetry, Purview DLP, and PowerShell.
🛠️ 1. Architecture: The M365 Native Shadow AI Discovery Pipeline
Direct Answer: The Microsoft 365 native Shadow AI discovery pipeline relies on kernel-level network inspection in Microsoft Defender for Endpoint (MsMpEng.exe), streaming HTTPS domain queries to the Cloud Discovery dashboard without network proxy bottlenecks.
+-----------------------------------------------------------------------------------+
| Microsoft 365 Native Shadow AI Discovery & Enforcement Architecture |
+-----------------------------------------------------------------------------------+
| [User Endpoint Activity] |
| - Edge / Chrome / Developer Terminal / Standalone Desktop AI Apps |
| │ |
| ▼ |
| [Microsoft Defender for Endpoint: Network Protection Engine] |
| - Inspects Outbound HTTPS Handshakes & DNS Resolutions |
| - Logs Event ID 1125 (Network Inspection Block) / 1126 (Audited Connection) |
| │ |
| ▼ (Encrypted Cloud Telemetry Stream) |
| [Microsoft Defender Portal: security.microsoft.com] |
| +─────────────────────────────────────────────────────────────────────────────+ |
| | Cloud Apps > Cloud Discovery Dashboard | |
| | - Filter Category: "Generative AI" (600+ Tracked AI Platforms) | |
| | - Metrics: Total Traffic, Upload Volume (Exfiltration Risk), Unique Users | |
| +──────────────────────────────────────┬──────────────────────────────────────+ |
| │ |
| ▼ |
| [Microsoft Purview AI Hub & DLP] ◄──────┴──────► [Defender Indicators & Filtering] |
| - Classifies Sensitive Info Types (SIT) - Tags App: "Unsanctioned" |
| (API Keys, Source Code, PII) - Pushes Block Rule to Edge/OS |
| - Enforces Data Loss Prevention - Redirects to Copilot Enterprise|
+-----------------------------------------------------------------------------------+
By inspecting network handshakes directly at the operating system layer, Microsoft Defender captures telemetry from remote workers, home Wi-Fi connections, and travel hotspots—completely eliminating the blind spots inherent to traditional corporate perimeter firewalls.
🔍 2. Step 1: Access Cloud Discovery in the M365 Defender Portal
Direct Answer: Access the native Cloud Discovery engine in Microsoft Defender to view automated categorizations for over 600 generative AI platforms without deploying third-party agent software.
- Navigate to the Microsoft Defender Portal (
https://security.microsoft.com). - In the left navigation menu, expand Cloud Apps and select Cloud Discovery.
- Click the Discovered Apps tab along the top navigation bar.
- Click Filter, select App Category, and check Generative AI.
- Click Apply.
Microsoft automatically tags traffic against a curated catalog of over 600 recognized AI services, including OpenAI, Anthropic, DeepSeek, Midjourney, Perplexity, and Hugging Face.
📊 3. Enterprise Shadow AI Risk & Data Exfiltration Matrix
Direct Answer: Evaluate your organization’s highest-traffic AI tools against our compliance matrix to measure data retention, training consent, and Microsoft risk ratings.
Sort the filtered Generative AI list by Upload Data Volume descending. On our enterprise workbench audits, sorting by upload volume immediately reveals which departments are pasting megabytes of internal files into untrusted services:
| AI Platform & Service | Microsoft Risk Score (1-10) | Public Model Training On Prompts? | Enterprise Data Protection (EDP)? | Recommended Policy Action |
|---|---|---|---|---|
| ChatGPT (Free / Plus Consumer) | 6 (Medium) | Yes (Default opt-in) | ❌ None | Block via Defender Web Filtering |
| DeepSeek Web (chat.deepseek.com) | 4 (High Risk) | Yes (Server-side retention) | ❌ None | Block via Network Protection |
| Claude.ai (Free Consumer Tier) | 6 (Medium) | Yes (Unless opt-out requested) | ❌ None | Block; offer sanctioned alternative |
| Perplexity.ai (Free Consumer) | 6 (Medium) | Yes (Enabled by default) | ❌ None | Block; enforce corporate search |
| Microsoft Copilot with EDP | 10 (Sanctioned) | No (Strict zero-retention SLA) | ✅ Full HIPAA / GDPR / ISO compliance | Sanction & redirect all staff |
Focus your initial security triage on any service with a Risk Score below 7 where employees have uploaded more than 100 MB of data over the past 30 days.
🛡️ 4. Step 2: Correlate Data Exfiltration with Microsoft Purview
Direct Answer: Leverage Microsoft Purview AI Hub and Data Loss Prevention (DLP) policies to detect whether pasted text contains credit card numbers, API credentials, or customer PII.
Knowing which app employees visited is only half the battle; security teams must verify what data left the perimeter.
- Open the Microsoft Purview Compliance Portal (
https://purview.microsoft.com). - Navigate to AI Hub (Preview) or Data Loss Prevention > Alerts.
- Review matches against Sensitive Information Types (SIT):
- Search for triggers on
Azure API Credentials,SQL Connection Strings,Credit Card Numbers, orEmployee Identification Numbers.
- Search for triggers on
- Review the user audit trail to determine if the prompt paste was a routine productivity task or an intentional exfiltration vector.
⚡ 5. Automated Developer Artifact: Audit-ShadowAIEndpoints.ps1
Direct Answer: Run our team’s automated PowerShell triage script to audit local workstation DNS caches, Defender Network Protection block events, and generate an exportable CSV risk summary.
To help IT administrators immediately verify whether unmanaged consumer AI endpoints are actively being queried on managed endpoints, our engineering team developed Audit-ShadowAIEndpoints.ps1. Run this non-destructive script in an elevated PowerShell session:
<#
.SYNOPSIS
PraveenTechWorld - Endpoint Shadow AI Telemetry Audit Script
.DESCRIPTION
Scans local DNS resolver cache, active TCP connections, and Microsoft
Defender Network Protection event logs for unauthorized consumer AI usage.
#>
[CmdletBinding()]
param(
[string]$ExportCsvPath = "$env:USERPROFILE\Desktop\ShadowAI_Endpoint_Audit.csv"
)
Write-Host "============================================================" -ForegroundColor Cyan
Write-Host " PraveenTechWorld: M365 Endpoint Shadow AI Triage Tool " -ForegroundColor Cyan
Write-Host "============================================================" -ForegroundColor Cyan
# 1. Target Consumer AI Domain Registry
$TargetAIEngines = @(
@{ Name = "OpenAI ChatGPT"; Domain = "chatgpt.com"; Risk = "High" },
@{ Name = "DeepSeek Web"; Domain = "deepseek.com"; Risk = "Critical" },
@{ Name = "Anthropic Claude"; Domain = "claude.ai"; Risk = "High" },
@{ Name = "Perplexity AI"; Domain = "perplexity.ai"; Risk = "Medium" },
@{ Name = "Poe AI"; Domain = "poe.com"; Risk = "High" },
@{ Name = "Midjourney Web"; Domain = "midjourney.com"; Risk = "Medium" }
)
# 2. Check DNS Cache for Recent Resolutions
Write-Host "`n[*] Inspecting Local DNS Resolver Cache..." -ForegroundColor Yellow
$dnsCache = Get-DnsClientCache
$findings = [System.Collections.Generic.List[PSCustomObject]]::new()
foreach ($ai in $TargetAIEngines) {
$matchedRecord = $dnsCache | Where-Object { $_.Entry -like "*$($ai.Domain)*" }
if ($matchedRecord) {
Write-Host " [!] ACTIVE DNS TRACE FOUND: $($ai.Name) ($($ai.Domain))" -ForegroundColor Red
$findings.Add([PSCustomObject]@{
Timestamp = (Get-Date).ToString("yyyy-MM-dd HH:mm:ss")
Type = "DNS Cache Match"
Service = $ai.Name
Domain = $ai.Domain
RiskLevel = $ai.Risk
Detail = "Endpoint resolved domain within TTL cache window"
})
} else {
Write-Host " [+] Clean: No active cache for $($ai.Domain)" -ForegroundColor Green
}
}
# 3. Check Microsoft Defender Network Protection Event Logs
Write-Host "`n[*] Auditing Microsoft Defender Network Inspection Events..." -ForegroundColor Yellow
$defenderLog = "Microsoft-Windows-Windows Defender/Operational"
if (Get-WinEvent -ListLog $defenderLog -ErrorAction SilentlyContinue) {
# Event ID 1125: Network Protection Block | Event ID 1126: Network Protection Audit
$events = Get-WinEvent -FilterHashtable @{
LogName = $defenderLog
Id = 1125, 1126
StartTime = (Get-Date).AddDays(-7)
} -ErrorAction SilentlyContinue
if ($events) {
Write-Host " [+] Found $($events.Count) Network Protection security events in the last 7 days." -ForegroundColor DarkCyan
foreach ($ev in $events) {
$msg = $ev.Message
foreach ($ai in $TargetAIEngines) {
if ($msg -like "*$($ai.Domain)*") {
Write-Host " [!] DEFENDER TRIGGER: Event $($ev.Id) on $($ai.Domain)" -ForegroundColor Red
$findings.Add([PSCustomObject]@{
Timestamp = $ev.TimeCreated.ToString("yyyy-MM-dd HH:mm:ss")
Type = "Defender Event $($ev.Id)"
Service = $ai.Name
Domain = $ai.Domain
RiskLevel = $ai.Risk
Detail = "Defender triggered Web Content filter block/audit"
})
}
}
}
} else {
Write-Host " [+] No Defender Network Protection blocks recorded in past 7 days." -ForegroundColor Green
}
} else {
Write-Host " [-] Defender Operational event log not accessible" -ForegroundColor Gray
}
# 4. Export Findings to CSV
if ($findings.Count -gt 0) {
Write-Host "`n[!] Risk Findings Identified: $($findings.Count) items recorded." -ForegroundColor Yellow
$findings | Export-Csv -Path $ExportCsvPath -NoTypeInformation
Write-Host " [+] Exported forensic audit report to: $ExportCsvPath" -ForegroundColor Green
} else {
Write-Host "`n[+] Zero Shadow AI traces detected on this host. System compliant." -ForegroundColor Green
}
Write-Host "`n============================================================" -ForegroundColor Cyan
Write-Host " Audit Complete. Review exported CSV for security review. " -ForegroundColor Cyan
Write-Host "============================================================" -ForegroundColor Cyan
🚫 6. Step 3: Block Unsanctioned AI Endpoints via Web Content Filtering
Direct Answer: Tag high-risk generative AI tools as Unsanctioned in Defender for Cloud Apps to enforce automatic endpoint DNS and HTTPS blocks across your fleet.
Once you have documented consumer AI usage, configure Defender for Endpoint to block connection attempts:
- In the Defender Portal, return to Cloud Apps > Cloud Discovery > Discovered Apps.
- Select the checkbox next to ChatGPT, DeepSeek, or Claude.
- Click the Tag as Unsanctioned icon (circle with diagonal slash) at the top of the table.
- Microsoft Defender for Endpoint will sync this indicator to all enrolled Windows 10/11 devices within 15 minutes.
- When a user navigates to the domain in Microsoft Edge, Chrome, or Firefox, the Network Protection engine intercepts the socket and renders a corporate block banner.
🔀 7. Step 4: Route Employees to Sanctioned Enterprise Copilot
Direct Answer: Pair network blocks with educational browser redirects in Microsoft Edge for Business to prevent staff from moving Shadow AI activity to unmanaged personal devices.
Blocking tools without providing a viable alternative always backfires: employees will open mobile browsers or tether their personal smartphones to continue using AI.
- Open Microsoft Intune Admin Center (
https://intune.microsoft.com). - Navigate to Devices > Configuration > Manage Edge Policies.
- Configure the SmartScreen / Web Content Filter Block Page Redirect URL:
- URL:
https://m365.cloud.microsoft/chat(Enterprise Copilot).
- URL:
- When a user navigates to
chatgpt.com, Edge displays a clean prompt:“Access to consumer AI is restricted to protect corporate data. You have been redirected to Microsoft 365 Copilot, where Enterprise Data Protection is active.”
This turns security enforcement into a positive productivity booster rather than a frustrating roadblock.
📋 Shadow AI Audit Runbook Checklist
| Phase | Tool Used | Objective | Execution Metric |
|---|---|---|---|
| 1. Discovery | Defender for Cloud Apps | Filter Discovered Apps for Generative AI | Identify top 5 consumer AI web apps |
| 2. Risk Scored | Cloud Discovery | Sort by Upload Data Volume | Flag users uploading over 100 MB |
| 3. Content DLP | Microsoft Purview AI Hub | Check Sensitive Info Types (SIT) matches | Confirm no API keys or credentials leaked |
| 4. Host Audit | Audit-ShadowAIEndpoints.ps1 | Scan local workstation DNS caches & event logs | Export compliance verification CSV |
| 5. Enforcement | Defender for Endpoint | Tag consumer apps as Unsanctioned | Push zero-trust web content block |
| 6. Adoption | Microsoft Edge for Business | Redirect blocked traffic to Enterprise Copilot | Zero productivity loss; 100% data privacy |
🔗 Related Enterprise Security & Automation Guides
For further IT infrastructure runbooks from our team’s workbench, explore our companion guides:
- GPO Sprawl: How We Audited and Deleted 140 Zombie Policies: Active Directory Group Policy cleanup and PowerShell inventory scripts.
- ChatGPT Workplace Usage & Adoption Patterns in 2026: Empirical data on developer and office AI adoption.
- Best Business Password Managers in 2026: Security & Pricing Compared: Enterprise credential security and passkey deployments.
- Local LLM VRAM & Quantization Calculator: Calculate GPU memory requirements for running private, on-premise AI models.
- How to Run Local AI Models on Windows 11 with Phi-4 & DeepSeek: Complete workbench guide to private local AI inference with zero cloud data exposure.
Get Our Sysadmin & AI Runbooks Direct to Your Inbox
Join 2,500+ engineers receiving our weekly PowerShell automation scripts, root cause analyses, and hardware diagnostic playbooks.
Frequently Asked Questions: Shadow AI Audit: Detect Unauthorized AI in Microsoft 365
What is Shadow AI in the workplace?
Can Microsoft Defender track AI usage on non-company networks?
Why shouldn't IT just block all AI sites?
Official Technical References
- Microsoft Learn: Discover and manage Shadow AI using Defender for Cloud Apps — Microsoft Learn
- Microsoft Learn: Microsoft Purview AI Data Security and Governance — Microsoft Learn
- Microsoft Learn: Configure Web Content Filtering in Defender for Endpoint — Microsoft Learn
Add PraveenTechWorld as a preferred source in your Google Search results.
Explore more: Browse all it operations guides or check related articles below.


