A tool that provides visibility, control, and threat protection for cloud-based applications and services
Use Defender for Cloud Apps for org‑wide discovery and blocking, then add more granular controls with Microsoft Entra Internet Access and (optionally) Intune.
A practical approach in three layers:
- Discover and classify AI apps
- In the Microsoft Defender portal, go to Cloud apps → Cloud app catalog.
- In Category, select Generative AI.
- Review risk scores and usage, and tag apps as Sanctioned or Unsanctioned according to organizational policy.
- See the guidance in Step 1: Discover AI apps for using the catalog and risk scores.
- Block unsanctioned AI apps for the whole organization
- In Defender for Cloud Apps, after identifying AI apps that should be blocked for most users, select them in the Cloud app catalog.
- Mark them as Unsanctioned. This:
- Blocks them at the organizational level via Defender for Cloud Apps network controls.
- For devices onboarded to Defender for Endpoint, unsanctioned apps are automatically blocked (unless the security team configures “warn and educate” instead of hard block).
- Optionally, create an app governance policy that targets unsanctioned generative AI apps:
- Policy template: No template
- Apps matching all of the following:
Category equals Generative AIANDTag equals Unsanctioned - Apply to: All continuous reports This gives a default posture of “blocked for everyone” for those AI tools.
- Allow specific AI apps only for specific users/groups
Org‑wide unsanctioning is coarse‑grained. To allow exceptions (for example, developers) while keeping everyone else blocked, use Microsoft Entra Internet Access and related controls:
- Keep the AI apps Unsanctioned in Defender for Cloud Apps so they are blocked by default.
- Use Microsoft Entra Internet Access Conditional Access policies to selectively allow access:
- Create policies that:
- Target specific users or groups (for example, a “Developers” security group).
- Allow access to the specific AI app domains for those groups.
- Keep the default block in place for all other users.
- Create policies that:
- For elevated‑risk users, combine with Microsoft Purview Insider Risk Management Adaptive Protection:
- Users flagged as high risk can be automatically restricted from accessing AI apps, even if they belong to a normally allowed group.
- (Optional) Enforce device‑level controls
To prevent users from bypassing browser‑based controls by installing native AI clients:
- Use Microsoft Intune to block installation of unsanctioned AI apps on managed devices, following the guidance in “Blocking and removing apps on Intune managed devices”.
Resulting model:
- Defender for Cloud Apps: discovers all generative AI apps, provides risk scores, and enforces org‑wide “sanctioned/unsanctioned” posture.
- Microsoft Entra Internet Access: narrows access so only specific users/groups (for example, developers) can reach selected AI tools.
- Intune (optional): blocks installation of unsanctioned AI apps on devices.
References: