Skip to the main content.

Modernize & Transform

Built to help you reimagine IT operations, empower your workforce, and leverage AI-powered tools to stay ahead of the curve.

Untitled design (3)

Empower My Team

We bring together the best of Microsoft’s cloud ecosystem and productivity tools to help your people thrive.

Untitled design (3)

Build My Infrastructure

We offer a comprehensive suite of infrastructure services tailored to support your business goals today and scale for the future

Untitled design (3)

IT Services

Our managed and co-managed IT service plans deliver a responsive and innovative engagement to support your IT needs, improve employee experience, and drive growth for your business. 

Untitled design (3)

Cybersecurity Services

Sourcepass offers innovative solutions, including SOC, GRC, Security Assessments, and more to protect your business.

Untitled design (3)

Professional Services

Grow your business with cloud migrations, infrastructure refreshes, M&A integrations, staff augmentation, technical assessments, and more.

Untitled design (3)

Industries

We understand what most managed service providers don’t – when it comes to industry-specific technology, one-size-fits-all solutions don’t exist.

Untitled design (3)

Public Sector

Sourcepass GOV, a division of Sourcepass, is dedicated to providing specialized IT solutions for the public sector.

Untitled design (3)

Locations

We have coverage across the United States, with phyiscal locations across 8 states. Wherever you are, Sourcepass has your back.

Untitled design (3)

Resource Library

Stay ahead, stay connected, and discover the future of IT with Sourcepass.

Untitled design (3)

Events & Webinars

Dive into a dynamic calendar of webinars and in-person gatherings designed to illuminate the latest in managed IT services, cybersecurity, and automation.

Untitled design (3)

Resources by Role

Explore key resources, eBooks, video trainings, and more curated for CEOs, CFOs, CIOs, CISOs, and technology leaders!

Untitled design (3)

The Sourcepass Story

Sourcepass aims to be different. It is owned and operated by technology, security, and managed services experts who are passionate about delivering an IT experience that clients love.

Untitled design (3)

The Sourcepass Experience

At Sourcepass, we’re rewriting the IT and cybersecurity experience by helping businesses focus on what they do best, while we deliver the infrastructure, insights, and innovation to help them thrive.

Untitled design (3)

 

How to Detect and Block Shadow AI in Microsoft 365

 
How to Detect and Block Shadow AI in Microsoft 365

29% of employees have already used sanctioned AI agents for work tasks, according to Microsoft's Cyber Pulse report.

A 2026 study from LayerX Security found that 6% of employees pasted sensitive data into GenAI and 4% did so weekly, with certain platforms exceeding 12%. If you are running Microsoft 365 and do not have shadow AI controls in place, that data is leaving your environment every time someone pastes a contract into ChatGPT or uploads a spreadsheet to a consumer AI tool.

Microsoft has been building the tooling to address this across the browser, the network, and the data layer. Here is what is currently available and how it works.

 

What is Shadow AI in Microsoft 365?

 

Shadow AI refers to the use of generative AI tools by employees without organizational knowledge or governance. It follows a similar trajectory to shadow IT, but with a meaningful distinction. Shadow IT was about unapproved software operating on a network. Shadow AI is a data egress problem.

Whether it is a prompt containing client data, a file upload to an unmanaged platform, or customer information shared in an AI chat, organizational data is leaving the environment. That data may be retained by the AI provider, used in model training, or simply persist outside the organization with no record of its departure.

 

Why Standard Security Tools Miss Shadow AI

 

Standard security tooling is designed to detect threats. Shadow AI does not present as one.

It looks like normal HTTPS traffic to legitimate domains like ChatGPT, Claude, Gemini and DeepSeek. These are trusted TLS endpoints that most URL filters categorize as productivity tools. Most DLP policies monitor for credit card numbers or patient identifiers moving to known file-sharing sites. They are not evaluating content pasted into an AI chat interface.

A CASB helps to monitor sanctioned applications. It does not have visibility into what users type in a browser tab outside of those applications. Even with tools like Cloud App Security in the Microsoft stack, the various components often struggle to capture all of that activity.

This is not a misconfiguration. It is a category of data movement that did not exist when most security architectures were designed. According to Microsoft's 2026 Data Security Index, 86% of data security leaders now prefer integrated platforms over fragmented tools, and 47% of organizations are actively implementing GenAI controls, up 8% year over year.

Microsoft has recognized this gap and built a layered response directly within Microsoft 365.

 

How Edge for Business Blocks Shadow AI at the Browser Level

 

A significant portion of shadow AI activity originates in the browser. A user opens a tab, navigates to an unmanaged AI platform, and begins submitting prompts.

Microsoft Edge for Business now includes in-browser managed DLP powered by Purview that monitors prompts being generated in the browser. Here is how it functions:

  • Prompts and file uploads are analyzed in real time.
  • Sensitive data triggers an immediate audit or block action.
  • Blocked users receive a policy-based notification explaining the restriction.
  • A redirect option routes the user to Microsoft 365 Copilot, where enterprise data protections are enforced.

Because these controls are integrated with Entra ID, they can be scoped precisely. They apply to Edge on both managed and unmanaged devices, provided users are signed into their Microsoft 365 account in Edge. Edge for Business settings also prevent users from bypassing controls by switching to an alternate browser.

Worth noting: This assumes Edge is being enforced as the primary browser. If it is not, additional controls through Intune or Conditional Access policies are necessary to address that gap.

 

How Global Secure Access Detects Shadow AI at the Network Layer

 

Browser-level controls are valuable, but they do not provide full coverage. Microsoft Entra Internet Access, part of the Global Secure Access suite, introduces network-layer detection that became generally available in 2026.

This capability identifies previously unknown AI applications in use by analyzing traffic flowing to and from endpoints. It captures activity that endpoint management and browser controls cannot observe.

Global Secure Access accomplishes this by:

  • Inspecting internet and Microsoft 365 traffic for connections to known generative AI applications, AI model provider frameworks, and SaaS AI services.
  • Matching discovered applications against the Defender for Cloud Apps catalog, which assigns risk scores based on security, compliance, and legal factors.
  • Surfacing usage insights through the Application Usage Analytics dashboard, including which users are active, frequency of use, and volume of data being transferred.

Once deployed, you gain visibility into which AI tools are in use. You can quantify the data volume moving to those tools. And you can determine the appropriate response from there.

 

How Microsoft Purview Prevents Sensitive Data from Reaching AI Tools

 

On top of the browser and network layers, Microsoft announced additional Purview capabilities at RSA that extend protection across a broader surface area:

  • Blocking PII, financial data, and intellectual property from inclusion in AI prompts across applications and agents.
  • Customizable reporting that provides visibility into what data is being shared and through which channels.
  • Expanded DLP coverage across a broader list of third-party AI tools services beyond the initial supported set.

 

How Browser, Network, and Data Controls Work Together

 

No single tool resolves the shadow AI problem in isolation. The value is in how these layers operate together:

 

Layer

Tool

What It Addresses

Browser

Edge for Business + Purview DLP

Text prompts and supported file-upload scenarios

Network

Entra Internet Access (Global Secure Access)

Traffic to AI applications that bypass browser controls

Data

Purview DLP

PII, financial data, and IP in AI prompts across applications and agents

 

Each layer addresses a distinct vector. Edge covers what happens in the browser. Global Secure Access covers what moves across the network. Purview DLP governs what sensitive data is permitted to reach AI tools in the first place.

 

How to Start Blocking Shadow AI in Microsoft 365

 

If shadow AI governance is not yet on the roadmap, here is a good starting point:

  1. Enable shadow AI discovery in Global Secure Access to establish a baseline of which AI tools are in use across the organization.
  2. Deploy Purview inline DLP in Edge for Business to begin monitoring and controlling data being submitted to unmanaged AI platforms through the browser.
  3. Review existing Purview DLP policies to ensure they account for AI prompts as a data channel, not solely traditional file sharing and email.

The tooling is available and the deployment guidance is documented. Whether the starting point is discovery, DLP enforcement, or network-layer visibility, the controls within Microsoft 365 are ready to be deployed.

Frequently Asked Questions about Shadow AI in Microsoft 365

Is your Organization Ready for Shadow AI Governance?

 

Shadow AI governance is quickly becoming a baseline exception, not a differentiator. Microsoft has invested heavily in giving organizations the tools to detect, monitor and block unsanctioned AI usage across the full Microsoft 365 environment. The gap between organizations that have these controls in place and those that do not is only getting wider, and the cost of closing it after a data incident is significantly higher than the cost of deploying them now.

If this is something your team has been thinking about, the Sourcepass Center of Excellence for Microsoft works with organizations every day on exactly this. We are happy to take a look at your environment and help you figure out where to start.

 

 

Want help planning your Microsoft AI adoption?

 

Want to go deeper on Microsoft 365 security?