Shadow AI in Microsoft 365 admin center (Preview)

Important

This feature is part of Frontier preview program. Frontier connects you directly with Microsoft's latest AI innovations. Frontier previews are subject to the existing preview terms of your customer agreements. As these features are still in development, their availability and capabilities might change over time.

The Shadow AI page in the Microsoft 365 admin center helps IT administrators discover, monitor, and govern unmanaged AI agents used within their organization.

This preview capability provides a dedicated view for detecting and governing unapproved AI agents such as OpenClaw, and enables administrators to take governance actions to maintain security and compliance.

Note

Shadow AI is currently in public preview. Features, supported agents, and behaviors might change before general availability.

Prerequisites

To use Shadow AI detection and governance, you need:

What is Shadow AI?

Shadow AI refers to consumer-facing AI applications and standalone agents deployed across your organization without IT visibility or approval. These agents can operate autonomously on user devices, creating blind spots in your security and compliance posture. While these agents can boost productivity, unmanaged usage introduces significant risks, such as the following:

  • Data leakage.
  • Compliance violations.
  • Security vulnerabilities.
  • Lack of auditability and governance.

The Shadow AI experience helps administrators identify and manage these risks without disrupting legitimate business workflows.

Available features

During public preview, the Shadow AI experience allows admins the following capabilities:

Agent Detection Blocking
OpenClaw Available Available
ChatGPT Desktop Available Not available
Ollama Desktop Available Not available
Poe Desktop Available Not available
Claw/ZeroClaw Available Not available
OpenCode Available Not available
Claude Desktop Available Not available

Note

Shadow AI blocking currently apply only to managed Windows devices enrolled with Microsoft Intune.

Access the Shadow AI (Frontier) agent

The Shadow AI (Frontier) page in the Microsoft 365 admin center is a dedicated experience separate from the All agents page. It focuses exclusively on unmanaged AI agents that require detection and governance.

To access the Shadow AI (Frontier) page in the Microsoft 365 admin center, follow these steps:

  1. Sign in to the Microsoft 365 admin center.
  2. Select Agents > Shadow AI.
    The Shadow AI (Frontier) page displays a list of known Shadow AI agents that can be detected in your environment.

View Shadow AI agent details

  1. To view Shadow AI agent details, such as OpenClaw details, select the Shadow AI agent from the list of agents in the Shadow AI (Frontier) page.
    The details pane opens for the selected Shadow AI agent.

  2. Confirm Details is selected.
    The Details pane provides the following agent information:

    • Details tile:

      • First accessed: Date the agent was first accessed.
      • Most recent activity: Date the agent was last used.
      • Last scanned: Date the agent was last detected.
    • Detections tile:

      • Devices: Count of devices that this agent is detected running on.
      • Users: Unique count of users that are detected using this agent.
    • Security policies tile: Displays if a blocking Intune policy has been applied to prevent this agent from running.

    • Total traffic tile:

      • Unique endpoints: Number of unique fully qualified domain names (FQDN) the agent accessed.
      • Requests: Number of network requests made by the agent.
      • Data sent: Network traffic sent by the agent.
      • Data received: Network traffic received by the agent.

Note

The following fields and tiles will only be populated with data if Global Secure Access (GSA) has been enabled:

  • Total traffic tile.
  • Users field.
  • Most recent activity field.
  • Last scanned field.

View detected devices for a Shadow AI agent

You can view detected devices in the Shadow AI agent details pane by following these steps:

  1. In the Shadow AI agent details pane, select the Detected devices tab.

    A list of detected devices is displayed.

  2. In Detected devices, you can search for a specific device name. You can also see the following device data:

    • Device name: Name of the device.
    • Model: Type of device (Desktop, Virtual Machine, Server, Laptop, etc.)
    • Operating system: Operating system installed on the device.
    • Last Seen: The last time Microsoft Defender detected the agent on the device.

Blocking a Shadow AI agent

After detection is enabled and the Shadow AI agent is identified in your environment, you can block it to prevent execution on managed devices. When a Shadow AI agent is blocked, such as OpenClaw, it blocks common ways of running it by creating a new Microsoft Intune policy that automatically propagates to all managed Windows devices enrolled in Intune.

To view the policy details, search for the policy name A365 - Block OpenClaw in the article Assign policies in Microsoft Intune. Depending on how Intune is configured in your organization, this Intune policy update could take anywhere from 15 minutes up to 8 hours to apply. Full policy details, including when Intune policy applies, can be found in Intune. Lastly, policies can also be edited in Intune to add additional controls.

To block a Shadow AI agent, follow these steps:

  1. In the Shadow AI agent details pane, select Security policies.

  2. Under Security policies, select Block > Apply Policies.