RB-004 High
Unauthorized AI browser extension or OAuth grant
DET-MS-MDE-001 detects a high-risk AI browser extension on a managed endpoint, OR DET-MS-MCAS-002 detects an OAuth grant to an AI app over Microsoft Entra ID with sensitive permissions.
Triggers
Immediate response (first hours)
- L1 SOC analyst: Confirm extension ID / app ID against the service catalog. For OAuth grants, capture granted permissions and the user who consented.
- L2 SOC analyst: For OAuth grants with broad permissions (Mail.ReadWrite, Files.ReadWrite.All, admin-consent): pause the app in Defender for Cloud Apps; revoke consent in Entra ID.
- L2 SOC analyst: For extensions: trigger Chrome/Edge Enterprise force-uninstall via policy if not already auto-enforced. Confirm uninstall in subsequent telemetry.
Short-term response (within days)
- AI Governance triage: Notify user with comms/extension-warning or comms/oauth-warning. Provide approved-tool alternatives. (Within 5 business days)
- Security architecture: If the extension/app is broadly requested for legitimate work, evaluate enterprise version or alternative for sanctioning (RB-003 process).
Long-term response (weeks+)
- Security architecture: Tighten preventive controls: tighten Chrome Enterprise extension allow-list; tighten Entra user-consent policy (admin-consent required for sensitive scopes).
- AI Governance triage (quarterly): Trend repeat rate and category mix. Adjust comms and policy accordingly.
Decision tree
- Does the extension / OAuth app have access to sensitive data?
- Yes → Immediate revoke + user comms.
- No → Comms only; allow until next review cycle.
- Is there organic demand for the underlying capability?
- Yes → Evaluate sanctioned alternative via RB-003.
- No → Maintain block and communicate.
RACI
- Responsible: L1/L2 SOC analyst
- Accountable: Security architecture lead
- Consulted: AI Governance triage, User's direct manager
- Informed: AI Governance Committee (aggregate quarterly)
Metrics to capture
- Time from detection to extension uninstall / OAuth revoke (target: ≤ 24 hours)
- Number of OAuth grants per quarter by sensitivity tier
- Extension reinstallation rate after uninstall (signal of unmet need)
Comms templates
comms-extension-warningcomms-oauth-warningcomms-approved-tool-announcement
Framework mappings
- NIST AI RMF: GOVERN-4.1, MANAGE-2.2
- ISO/IEC 42001: 8.2
- NIST CSF: PR.AC-4, DE.CM-7, RS.MI-1