Microsoft Defender for Endpoint
The endpoint signal for hybrid working — Defender for Endpoint's agent reports from the device wherever it is, so AI tools used in a browser off the corporate network (e.g. a home laptop with a personal login) still show up, alongside installed AI software.
What we read (read-only): device network events (egress to AI domains) and the software inventory.
Setup:
- In your tenant, grant the govn.ai application admin consent for the read-only permissions
AdvancedQuery.Read.AllandSoftware.Read.All. - In govn.ai: Shadow AI → Connections → Defender for Endpoint → enter your Azure tenant ID → Connect.
Requires Defender for Endpoint (E5 / Plan 2). Syncs daily; we store only AI finds. Privacy: device-traffic monitoring — see Privacy & data handling for discovery.
Who: admins and owners.