Microsoft Defender for Endpoint

The endpoint signal for hybrid working — Defender for Endpoint's agent reports from the device wherever it is, so AI tools used in a browser off the corporate network (e.g. a home laptop with a personal login) still show up, alongside installed AI software.

What we read (read-only): device network events (egress to AI domains) and the software inventory.

Setup:

  1. In your tenant, grant the govn.ai application admin consent for the read-only permissions AdvancedQuery.Read.All  and Software.Read.All .
  2. In govn.ai: Shadow AI → Connections → Defender for Endpoint → enter your Azure tenant ID → Connect.

Requires Defender for Endpoint (E5 / Plan 2). Syncs daily; we store only AI finds. Privacy: device-traffic monitoring — see Privacy & data handling for discovery.

Who: admins and owners.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.