Reference

Shadow AI Agent

Unmanaged local AI tools and agents (chatbots, coding assistants, local models, agentic CLIs) detected on Intune-managed devices that were not approved by IT.

Part of the Microsoft Agent 365 inventory.

Scan settings

Default scanning intervalAllowed scanning intervalsData removal during incremental scan
DailyDaily, Weekly, Bi-Weekly, Monthly, Never, InitialYes

Properties

Property Type Description Automation placeholder
Category String Type of AI tool: Agentic CLI, Local AI, Chatbot, Code Assistant, Image Generation, or Writing Assistant. Allowed values: Agentic CLI, Chatbot, Code Assistant, Image Generation, Local AI, Writing Assistant. {{ShadowAIAgent.Category}}
Initially Scanned DateTime Shows when this object was initially found in a scan. {{ShadowAIAgent.CreatedTime}}
Device count Int32 Number of managed devices the agent is detected on. {{ShadowAIAgent.DeviceCount}}
Display Name String {{ShadowAIAgent.DisplayName}}
Id String Microsoft Graph detected-app identifier. {{ShadowAIAgent.Id}}
Is approved Boolean True when an administrator has marked this agent as sanctioned. Approved agents are excluded from the Shadow AI policies. {{ShadowAIAgent.IsApproved}}
Is blocked Boolean True when a block policy has been applied for this agent. {{ShadowAIAgent.IsBlocked}}
Last scan update DateTime Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. {{ShadowAIAgent.LastModifiedTime}}
Last scanned DateTime Last time the agent was seen during an Intune scan. {{ShadowAIAgent.LastScan}}
Matched name String The catalog entry that classified this app as an AI agent. {{ShadowAIAgent.MatchedName}}
Platform String Platform the detected app runs on. {{ShadowAIAgent.Platform}}
Publisher String Publisher of the detected app as reported by Intune. {{ShadowAIAgent.Publisher}}
Risk Score Int32 Stores risk score {{ShadowAIAgent.RiskScore}}
Risk Score Update DateTime Stores risk score update {{ShadowAIAgent.RiskScoreLastUpdate}}
Risk Score Value String Stores risk score value like Low_Low {{ShadowAIAgent.RiskScoreValue}}
Version String Version of the detected app. {{ShadowAIAgent.Version}}

Relations

Relation Service Description
Shadow AI Detection Microsoft Agent 365 A detection of a shadow AI agent on a specific managed device, linked to the device's Microsoft 365 user.

Segments

Segment Description
Shadow AI: Agentic CLIs Lists unapproved local agentic AI CLIs and coding agents (OpenClaw, Claude Code, GitHub Copilot CLI, Aider, Cline, etc.).
Shadow AI: All Agents Lists all unapproved shadow AI tools and agents detected on managed devices.
Shadow AI: Local AI Lists unapproved locally-running AI model runners (Ollama, LM Studio, GPT4All, etc.).

Actions

This object does currently not have any actions.

Policy Severity Description
Shadow AI agent detected on managed devices Medium Flags unapproved AI tools and agents detected on Intune-managed devices.
Shadow AI: agentic AI CLI detected High Flags unapproved local agentic AI CLIs and coding agents on managed devices - the highest-risk shadow AI class.

Last updated: 7/19/2026