Microsoft Sentinel
The highest-coverage connector: one read-only query over your Log Analytics workspace finds traffic to AI domains across whatever you feed into Sentinel — firewalls, proxies, DNS — on or off the corporate network. A single connection covers your whole estate.
Setup:
- In the Azure portal, on your Log Analytics workspace (or subscription): Access control (IAM) → add the Log Analytics Reader role to the govn.ai application.
- Note your Azure tenant ID and Log Analytics workspace ID (both on the workspace Overview / your Entra Overview).
- In govn.ai: Shadow AI → Connections → Microsoft Sentinel → enter both IDs → Connect.
We run a built-in, vendor-neutral query (Microsoft's ASIM DNS / web-session parsers) — no changes to your workspace. Syncs daily; Sync now available. We store only AI-domain matches.
Requires an Azure admin to assign the role. Who: admins and owners.