5 min read

How to Detect and Block Shadow AI in Microsoft 365

How to Detect and Block Shadow AI in Microsoft 365

29% of employees have already used sanctioned AI agents for work tasks, according to Microsoft's Cyber Pulse report. 

A 2026 study from LayerX Security found that 6% of employees pasted sensitive data into GenAI and 4% did so weekly, with certain platforms exceeding 12%. If you are running Microsoft 365 and do not have shadow AI controls in place, that data is leaving your environment every time someone pastes a contract into ChatGPT or uploads a spreadsheet to a consumer AI tool. 

Microsoft has been building the tooling to address this across the browser, the network, and the data layer. Here is what is currently available and how it works. 

 

What is Shadow AI in Microsoft 365?

 

Shadow AI refers to the use of generative AI tools by employees without organizational knowledge or governance. It follows a similar trajectory to shadow IT, but with a meaningful distinction. Shadow IT was about unapproved software operating on a network. Shadow AI is a data egress problem.

Whether it is a prompt containing client data, a file upload to an unmanaged platform, or customer information shared in an AI chat, organizational data is leaving the environment. That data may be retained by the AI provider, used in model training, or simply persist outside the organization with no record of its departure.

 

Why Standard Security Tools Miss Shadow AI 

 

Standard security tooling is designed to detect threats. Shadow AI does not present as one.

It looks like normal HTTPS traffic to legitimate domains like ChatGPT, Claude, Gemini and DeepSeek. These are trusted TLS endpoints that most URL filters categorize as productivity tools. Most DLP policies monitor for credit card numbers or patient identifiers moving to known file-sharing sites. They are not evaluating content pasted into an AI chat interface.

A CASB helps to monitor sanctioned applications. It does not have visibility into what users type in a browser tab outside of those applications. Even with tools like Cloud App Security in the Microsoft stack, the various components often struggle to capture all of that activity.

This is not a misconfiguration. It is a category of data movement that did not exist when most security architectures were designed. According to Microsoft's 2026 Data Security Index, 86% of data security leaders now prefer integrated platforms over fragmented tools, and 47% of organizations are actively implementing GenAI controls, up 8% year over year. 

Microsoft has recognized this gap and built a layered response directly within Microsoft 365.

 

How Edge for Business Blocks Shadow AI at the Browser Level 

 

A significant portion of shadow AI activity originates in the browser. A user opens a tab, navigates to an unmanaged AI platform, and begins submitting prompts.

Microsoft Edge for Business now includes in-browser managed DLP powered by Purview that monitors prompts being generated in the browser. Here is how it functions:

  • Prompts and file uploads are analyzed in real time.

  • Sensitive data triggers an immediate audit or block action.

  • Blocked users receive a policy-based notification explaining the restriction.

  • A redirect option routes the user to Microsoft 365 Copilot, where enterprise data protections are enforced.

Because these controls are integrated with Entra ID, they can be scoped precisely. They apply to Edge on both managed and unmanaged devices, provided users are signed into their Microsoft 365 account in Edge. Edge for Business settings also prevent users from bypassing controls by switching to an alternate browser.

Worth noting: This assumes Edge is being enforced as the primary browser. If it is not, additional controls through Intune or Conditional Access policies are necessary to address that gap.

 

How Global Secure Access Detects Shadow AI at the Network Layer 

 

Browser-level controls are valuable, but they do not provide full coverage. Microsoft Entra Internet Access, part of the Global Secure Access suite, introduces network-layer detection that became generally available in 2026.

This capability identifies previously unknown AI applications in use by analyzing traffic flowing to and from endpoints. It captures activity that endpoint management and browser controls cannot observe.

Global Secure Access accomplishes this by:

  • Inspecting internet and Microsoft 365 traffic for connections to known generative AI applications, AI model provider frameworks, and SaaS AI services. 
  • Matching discovered applications against the Defender for Cloud Apps catalog, which assigns risk scores based on security, compliance, and legal factors. 
  • Surfacing usage insights through the Application Usage Analytics dashboard, including which users are active, frequency of use, and volume of data being transferred. 

Once deployed, you gain visibility into which AI tools are in use. You can quantify the data volume moving to those tools. And you can determine the appropriate response from there.

 

How Microsoft Purview Prevents Sensitive Data from Reaching AI Tools 

 

On top of the browser and network layers, Microsoft announced additional Purview capabilities at RSA that extend protection across a broader surface area:

  • Blocking PII, financial data, and intellectual property from inclusion in AI prompts across applications and agents. 
  • Customizable reporting that provides visibility into what data is being shared and through which channels. 
  • Expanded DLP coverage across a broader list of third-party AI tools services beyond the initial supported set. 

 

How Browser, Network, and Data Controls Work Together 

 

No single tool resolves the shadow AI problem in isolation. The value is in how these layers operate together:

 

Layer

Tool

What It Addresses

Browser

Edge for Business + Purview DLP

Text prompts and supported file-upload scenarios

Network

Entra Internet Access (Global Secure Access)

Traffic to AI applications that bypass browser controls

Data

Purview DLP

PII, financial data, and IP in AI prompts across applications and agents

 

Each layer addresses a distinct vector. Edge covers what happens in the browser. Global Secure Access covers what moves across the network. Purview DLP governs what sensitive data is permitted to reach AI tools in the first place.

 

How to Start Blocking Shadow AI in Microsoft 365

 

If shadow AI governance is not yet on the roadmap, here is a good starting point:

  1. Enable shadow AI discovery in Global Secure Access to establish a baseline of which AI tools are in use across the organization.
  2. Deploy Purview inline DLP in Edge for Business to begin monitoring and controlling data being submitted to unmanaged AI platforms through the browser.
  3. Review existing Purview DLP policies to ensure they account for AI prompts as a data channel, not solely traditional file sharing and email.

The tooling is available and the deployment guidance is documented. Whether the starting point is discovery, DLP enforcement, or network-layer visibility, the controls within Microsoft 365 are ready to be deployed. 

Frequently Asked Questions about Shadow AI in Microsoft 365 

Is your Organization Ready for Shadow AI Governance?

 

Shadow AI governance is quickly becoming a baseline exception, not a differentiator. Microsoft has invested heavily in giving organizations the tools to detect, monitor and block unsanctioned AI usage across the full Microsoft 365 environment. The gap between organizations that have these controls in place and those that do not is only getting wider, and the cost of closing it after a data incident is significantly higher than the cost of deploying them now. 

If this is something your team has been thinking about, the Sourcepass Center of Excellence for Microsoft works with organizations every day on exactly this. We are happy to take a look at your environment and help you figure out where to start. 

 

Want help planning your Microsoft AI adoption?

Why AI Agents Need Governance in Microsoft 365

5 min read

Why AI Agents Need Governance in Microsoft 365

AI adoption is accelerating faster than most organizations can govern it. AI tools are appearing across businesses faster than most IT teams can...

Read the full article
Why Microsoft Copilot Rollouts Fail

4 min read

Why Microsoft Copilot Rollouts Fail

Most Copilot rollouts do not fail because the technology is weak. They fail because teams turn it on, browse a store full of agents, and hope value...

Read the full article
How to Run Microsoft Defender in Passive Mode Alongside your EDR

6 min read

How to Run Microsoft Defender in Passive Mode Alongside your EDR

There is a good chance you are paying for an endpoint security tool you have never turned on. Most organizations running Business Premium, E3 or E5...

Read the full article
What Agentic AI Means for Microsoft 365 Copilot Adoption

4 min read

What Agentic AI Means for Microsoft 365 Copilot Adoption

Most Microsoft 365 environments are paying for AI capabilities that almost no one is using. Copilot licenses sit idle, agentic features roll out...

Read the full article
How Microsoft Agent 365 Controls AI Agent Sprawl

1 min read

How Microsoft Agent 365 Controls AI Agent Sprawl

AI agents are multiplying faster than most organizations can track them.

Read the full article
Is Microsoft 365 E7 Worth the Upgrade from E5?

1 min read

Is Microsoft 365 E7 Worth the Upgrade from E5?

Many organizations running Microsoft 365 E5 are also paying separately for SASE products, zero trust tools, standalone identity platforms, and a...

Read the full article