Microsoft Sentinel

The highest-coverage connector: one read-only query over your Log Analytics workspace finds traffic to AI domains across whatever you feed into Sentinel — firewalls, proxies, DNS — on or off the corporate network. A single connection covers your whole estate.

Setup:

  1. In the Azure portal, on your Log Analytics workspace (or subscription): Access control (IAM) → add the Log Analytics Reader role to the govn.ai application.
  2. Note your Azure tenant ID and Log Analytics workspace ID (both on the workspace Overview / your Entra Overview).
  3. In govn.ai: Shadow AI → Connections → Microsoft Sentinel → enter both IDs → Connect.

We run a built-in, vendor-neutral query (Microsoft's ASIM DNS / web-session parsers) — no changes to your workspace. Syncs daily; Sync now available. We store only AI-domain matches.

Requires an Azure admin to assign the role. Who: admins and owners.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.