Field note
Shadow AI Discovery with Defender Cloud Apps
Shadow AI is surging in UK SMEs as staff try unvetted generative tools. Defender for Cloud Apps reveals unsanctioned AI tools and data exfiltration risks.
Generative artificial intelligence tools promise dramatic productivity improvements, but their rapid, unmanaged adoption across UK small and medium enterprises has created an acute security challenge: Shadow AI. Employees across sales, marketing, finance, and operations regularly test consumer AI chatbots, browser extensions, PDF summarisers, and transcription assistants. In doing so, they routinely paste unredacted customer data, proprietary business plans, financial projections, and confidential legal agreements into services operating under consumer terms of service.
Under standard consumer tier agreements, user prompts and uploaded documents are frequently retained for foundational model training or stored across jurisdictions that fail UK GDPR adequacy requirements. To protect corporate IP and maintain data privacy standards without stifling productivity, IT leaders must gain continuous visibility into unapproved generative tools and enforce automated technical boundaries across all corporate endpoints.
Quick answer
Use Microsoft Defender for Cloud Apps (MDA) integrated with Microsoft Defender for Endpoint (MDE) to automatically discover and govern generative AI tools across Windows and macOS devices. By activating Cloud Discovery through endpoint network telemetry, you can identify all unapproved AI applications without deploying on-premises proxy servers or installing intrusive network tap appliances. Filter discovered apps by the "Generative AI" category, evaluate vendor risk scores, and mark unapproved tools as "Unsanctioned". This instantly synchronises with Defender for Endpoint to block network traffic and redirect staff toward approved enterprise AI solutions.
Why this keeps happening
Shadow AI adoption is rarely malicious; it is driven by employees attempting to work faster and solve operational bottlenecks that standard corporate software suites fail to address.
Four primary drivers accelerate unsanctioned AI use across modern organisations:
- Frictionless Consumer Onboarding: Modern generative AI platforms require nothing more than a personal Google, Apple, or Microsoft account to start generating text, analysing spreadsheets, or translating code. There is zero enterprise procurement delay.
- Delayed Corporate AI Delivery: When leadership announces that corporate AI initiatives are under review without providing a sanctioned alternative, staff independently seek external tools to draft customer proposals, debug software, or summarise board papers.
- Misunderstanding of Data Protection Terms: Most non-technical users assume that entering information into a modern web app is private by default. They are unaware that consumer terms of service typically allow vendors to log inputs, inspect sessions for moderation, and train future machine learning models on submitted text.
- Endpoint Telemetry Blind Spots: Traditional corporate firewalls only monitor traffic when employees are working inside the physical office. Remote and hybrid workers operating from home Wi-Fi or coffee shops bypass conventional perimeter security unless endpoint agents monitor web connection attempts directly.
Fix path
Eliminating Shadow AI blind spots requires configuring automated endpoint discovery, establishing clear sanctioning criteria, and enforcing automated blocking across managed hardware.
Cloud Discovery endpoint integration
Rather than relying on manual firewall log parsing or cumbersome network redirects, modern Microsoft 365 environments leverage Microsoft Defender for Endpoint as an intelligent sensor.
To enable endpoint-driven Cloud Discovery:
- Connect Defender for Endpoint to Cloud Apps: In the Microsoft Defender XDR portal (
security.microsoft.com), navigate to Settings > Endpoints > Advanced features, and toggle on Microsoft Defender for Cloud Apps. This allows MDE on enrolled Windows 10/11 and macOS devices to stream web connection telemetry directly to Defender for Cloud Apps. - Confirm Network Protection Status: Ensure Network Protection is enabled in Block mode across all devices via Microsoft Intune endpoint security policies. Network Protection intercepts outbound HTTP and HTTPS connection attempts at the network socket layer, inspecting domains before encrypted payloads are transmitted.
- Filter Generative AI Discovered Apps: In Defender for Cloud Apps, open the Cloud Discovery dashboard, filter the view by App category = Generative AI, and review the aggregated telemetry.
Defender for Cloud Apps evaluates discovered services against an automated risk assessment framework consisting of over 90 legal, compliance, and security metrics, including:
- Whether the vendor complies with UK GDPR and holds SOC 2 Type II or ISO 27001 certifications.
- Whether customer prompt data is retained, encrypted at rest, and excluded from machine learning model training.
- The hosting jurisdiction and data center locations of the AI provider.
Sanctioning and blocking generative AI apps
Visibility alone does not mitigate risk; security teams must establish deterministic control over which AI services endpoints are permitted to communicate with.
Within the Defender for Cloud Apps catalogue, every cloud service can be classified under three governance states:
- Sanctioned: The organisation has formally evaluated the vendor, executed a commercial agreement with enterprise data protection guarantees (such as Microsoft 365 Copilot, Claude Enterprise, or an isolated Azure OpenAI deployment), and approved its use for business data.
- Monitored: The tool is permitted for non-confidential exploratory use while undergoing security and privacy review. Telemetry continues to record transaction volumes and user identities without blocking access.
- Unsanctioned: The application fails enterprise compliance standards, exposes data to public training, or represents an unacceptable security risk.
When an administrator marks a generative AI application as Unsanctioned, Defender for Cloud Apps automatically pushes an indicator of compromise (IoC) to Microsoft Defender for Endpoint within minutes.
When a user on a managed laptop attempts to navigate to the unapproved domain or transmit data through an API endpoint, Defender for Endpoint blocks the connection at the browser and socket level. The user is presented with a clear corporate notification explaining that the service is restricted under internal acceptable use policies, along with a link guiding them to the company's approved, sanctioned enterprise AI platform.
Practical SME workflow
A structured, five-stage governance programme allows UK SMEs to safely regain control over internal AI usage:
- Establish a 14-Day Discovery Baseline: Enable endpoint telemetry and monitor Cloud Discovery for two weeks without enforcing blocks. This surfaces the actual AI tools staff rely on, the volume of data uploaded, and the departments with the highest usage.
- Publish an Approved AI Product Catalogue: Clearly communicate which tools are approved for company business, which data categories may be processed, and which platforms are strictly prohibited.
- Implement Enterprise Commercial Tiers: If employees are heavily using ChatGPT or Claude for legitimate operational tasks, upgrade them to enterprise agreements that explicitly guarantee zero retention for model training and provide administrative audit logging.
- Enforce Unsanctioned Blocks on High-Risk Services: Mark unvetted consumer chatbots, questionable browser extensions, and anonymous code generation platforms as Unsanctioned to trigger automated endpoint blocks.
- Establish a Monthly Review Cadence: New generative AI tools launch every week. Designate an IT lead or security officer to review newly discovered apps in the Cloud Discovery portal on a monthly basis, ensuring newly emerging tools are promptly classified.
Risk and control
Managing unvetted cloud AI adoption requires addressing multiple layers of regulatory, technical, and operational exposure.
| Threat | Direct Risk | Mitigating Control |
|---|---|---|
| Model Training Ingestion | Proprietary trade secrets ingested into public LLMs | Sanction only enterprise-tier tools with zero-retention guarantees |
| UK GDPR Breach | Personal identifying data transferred outside approved jurisdictions | Block non-compliant AI services via Defender for Cloud Apps |
| Malicious Browser Extensions | Stolen session cookies and credential harvesting via fake AI plugins | Enforce browser extension allowlists via Intune configuration profiles |
| Uncontrolled Subscription Spend | Departmental credit cards used for duplicate consumer AI licences | Consolidate usage into centralized, enterprise-managed billing agreements |
| Phishing and Hallucination Exploits | Staff act on unverified legal or tax outputs from unvetted models | Mandate human-in-the-loop review for all external business deliverables |
What good evidence looks like
To verify robust AI governance during Cyber Essentials Plus preparations, client procurement assessments, or data protection officer audits, gather the following compliance records:
- Cloud Discovery Export: A monthly report from Defender for Cloud Apps showing all discovered Generative AI services, their risk scores, and their sanctioning status.
- Defender for Endpoint Indicators: Screenshot or script export from the Defender portal demonstrating active domain blocks against unapproved AI tools.
- Intune Network Protection Policy: Configuration proof confirming that Network Protection is configured in
Enabled (Block)status across all managed Windows and macOS endpoints. - AI Acceptable Use Policy Acknowledgment: Signed documentation confirming that staff have read, understood, and agreed to the organisation's generative AI security standards.
Keep the change reversible
Blocking generative AI tools must not cripple essential business workflows or force staff into cumbersome workarounds:
- Staged Rollouts via Pilot Groups: Before applying global blocks, deploy unsanctioned tags against a pilot group of endpoints or configure Network Protection in
Auditmode. This verifies that essential, previously unmapped business integrations (such as automated customer service APIs) are not disrupted. - Fast-Track Exception Process: Establish a rapid 24-hour review channel (via a dedicated IT ticketing category or Teams channel) where staff can request business evaluation of new AI utilities.
- Instant Unsanction Revocation: If an unapproved application is subsequently vetted and procured under an enterprise agreement, reclassifying the app to "Sanctioned" in the Defender portal restores full endpoint connectivity within 15 minutes.
The common mistake
The most common leadership error is issuing an absolute, sweeping ban on all generative AI tools via corporate email without offering a sanctioned alternative or technical enforcement. Staff facing aggressive deadlines will simply bypass network blocks by sending sensitive files to personal smartphones or personal unmanaged laptops to run them through consumer AI tools. Total prohibition invariably drives shadow AI further underground; effective security requires providing a safe, approved corporate platform paired with automated endpoint guardrails.
Related field note
To benchmark your organisation's current AI security controls, identify compliance blind spots, and assess your readiness for governed enterprise AI adoption, complete our free AI workflow readiness assessment.