Skip to main content
ShadowAI Defense GitHub
← All detections
DET-MS-MCAS-001 Defender for Cloud Apps Application Connector config Severity: Medium

Defender for Cloud Apps — Shadow AI discovery policy

Cloud-app discovery policy in Defender for Cloud Apps configured to surface AI services from firewall/proxy logs and flag unsanctioned use.

Rule

# Defender for Cloud Apps — Cloud Discovery policy
# Name: Shadow AI Discovery
# Trigger: Application is in category 'Generative AI' AND is not sanctioned
#
# Conditions:
#   - App category in (Generative AI, AI Code Generation, AI Productivity)
#   - App sanction status != Sanctioned
#   - Traffic > 10 MB OR users >= 5 in 7-day window
#
# Actions:
#   - Alert: medium severity
#   - Auto-tag app as 'Shadow AI'
#   - Generate ticket in AI Governance triage queue
#
# Additional configuration:
#   - Continuous discovery from firewall/proxy logs (Cisco, Palo Alto, Fortinet, Zscaler, etc.)
#   - Tagging rule: all apps in Generative AI category default to 'Monitored' until reviewed
#   - Block via Conditional Access App Control for any app tagged 'Block'

How it works

Defender for Cloud Apps catalogs thousands of SaaS applications including generative AI. The discovery feature ingests firewall/proxy logs and matches against the catalog. Continuous discovery + sanctioning workflow is the central pivot for Shadow AI program operation.

Required data sources

  • Defender for Cloud Apps licensed (MCAS / standalone)
  • Firewall / proxy / SWG logs ingested (Cisco ASA, Palo Alto, Fortinet, Zscaler, Netskope, etc.)
  • Or Defender for Endpoint as discovery source

Prerequisites

  • Microsoft 365 E5 or Defender for Cloud Apps standalone
  • Log ingestion configured (continuous from log collector, or scheduled upload)

Expected volume

After initial discovery sweep: 20–80 new AI apps catalogued in first week. Steady-state: 1–5 new apps per week.

False-positive guidance

Microsoft's app catalog occasionally mis-categorizes apps. Validate before sanctioning/blocking.

Tuning steps

  1. Sanction-review every Generative AI app within 30 days of first discovery.
  2. Sync sanction status weekly with the AI Inventory in the Governance Toolkit.
  3. Use Conditional Access App Control to block specific apps (vs. domain-level blocking) for granular control.

Framework mappings

  • NIST AI RMF: GOVERN-4.1, MANAGE-4.1
  • ISO/IEC 42001: 8.2, 8.4
  • NIST CSF: DE.CM-7, ID.AM-2

Related AI Controls Catalog entries