Blog

Microsoft Entra Internet Access: More transparency and control for AI applications

Detecting, controlling, and securing: How Microsoft Entra Internet Access protects you from shadow AI, prompt injection, and data leaks.
September 1, 2026
Picture of Florian Schnepf
Florian Schnepf
Picture of Florian Aschbichler
Florian Aschbichler

The introduction of generative AI tools has revolutionized the world of work – and at the same time created a new category of security risks. Employees use dozens of AI services, such as ChatGPT, Claude, Gemini, or specialized AI assistants, on a daily basis, often without the IT department’s knowledge or approval. This phenomenon has a name: Shadow AI.

Similar to shadow IT, which is the uncontrolled use of unauthorized software and cloud services, shadow AI refers to the use of AI tools outside a company’s IT governance framework. The difference is: The risk is potentially much more serious. While an unauthorized file-sharing tool mainly poses a risk of data loss, AI services can transfer sensitive business information, customer data, or intellectual property directly to external models – without the IT department having the slightest clue.

According to Microsoft, only 9% of organizations feel sufficiently prepared to address risks such as shadow AI, prompt injection attacks, and fragmented security controls. This is an alarming number, and is also a clear signal that action is needed here.

What is shadow AI – and why is it so dangerous?

Shadow AI arises when employees want (and are supposed to) use AI tools, but no officially approved alternatives are available – or when the onboarding process for new tools is simply too slow. The result: Developers paste internally classified code into ChatGPT, sales representatives upload customer data to an AI assistant, HR teams use public models to analyze job applications.

The risks are multiple:

  • Data leaks: Sensitive or confidential information is shared with external AI providers without proper oversight.
  • Compliance violations: GDPR, HIPAA, NIS2, and other regulations may be violated if personal data is processed without authorization.
  • Prompt injection: Attackers can use manipulated inputs to trick AI models into performing unintended actions or revealing sensitive information.
  • Inability to audit: Without insight into AI usage, it is virtually impossible to analyze security incidents after the fact.
  • Uncontrolled leaks: No one knows what the AI sends back to third parties or writes to external systems.

Microsoft Entra Internet Access: An answer to shadow AI

With Microsoft Entra Internet Access, a part of Global Secure Access, Microsoft has developed a direct solution to these challenges. Internet Access is a cloud-based, identity-driven Secure Web Gateway (SWG) that secures an organization’s entire outbound Internet traffic. It is not a traditional proxy tool, but rather a security layer fully integrated into the Microsoft Entra identity platform that combines network, identity, and endpoint control.

Internet Access offers the following key features for shadow AI:

1. Shadow AI Discovery: Visibility as the first step

The first step for controlling shadow AI is visibility. Shadow AI Discovery analyzes users’ network traffic and identifies all connections to generative AI applications and services, including ChatGPT, Claude, Gemini, DeepSeek, SaaS MCP servers, and AI model provider frameworks.

Detected applications are automatically synced with the Microsoft Defender for Cloud Apps Cloud App Catalog. This catalog categorizes apps and assigns risk scores based on general security and compliance criteria. Administrators can see it all at a glance:

  • Which AI apps are being used in the organization?
  • How many users are using a specific app?
  • What risk profile does the respective app have?
  • How high is the transferred data volume for each app?

This feature can be accessed via the Entra Admin Center under Global Secure Access → Applications → Insights & Analytics → Cloud Applications. The “Generative AI apps and tools” filter allows you to specifically filter and analyze all AI-related services.

Shadow AI Discovery not only helps security teams uncover unknown risks, but also provides the data-driven foundation for informed decisions: Which apps are blocked? Which are included in the official approval process?

2. Conditional access for AI applications

Visibility alone is not enough. Internet Access allows conditional access policies to be applied directly to detected AI applications. This means that security teams can respond based on the specific situation.

  • Low-risk apps that are eligible for approval are passed on to the regular approval process.
  • High-risk or non-compliant apps are blocked immediately.
  • Specific exceptions can be defined for certain user groups (e.g., developers).

This granular level of control allows companies to enable the use of AI without losing control. This is a key advantage over the blanket blocking approach used by many legacy solutions.

3. Blocking unsanctioned MCP servers

With the advent of the Model Context Protocol (MCP) as a standard for integrating AI models into enterprise workflows, a new level of risk is emerging: SaaS-based MCP servers. Internet Access allows you to specifically block access to unauthorized MCP servers via URL policies before they can even establish a connection to internal resources.

4. TLS inspections: A look inside the encrypted tunnel

Generative AI services communicate exclusively via encrypted HTTPS. Without TLS inspection, the actual content of this communication – namely the employees’ prompts and the models’ responses – remains invisible to security tools. Internet Access offers TLS inspection, which decrypts, inspects, and then re-encrypts HTTPS traffic.

This allows content filtering policies, DLP rules, and prompt policies to be applied to the actual content of AI communications – not just to metadata. To use this feature, a root CA certificate must be distributed to managed devices (e.g., via Microsoft Intune).

5. Prompt Shield: Protection from AI manipulation

Prompt Shield is one of the most innovative features of Entra Internet Access. It operates at the network level and inspects prompts in real time before they reach the AI model. Specifically, Prompt Shield detects and blocks:

  • Jailbreak attempts: Attempts to manipulate AI models to circumvent their security policies.
  • Data leaks due to prompt injection: Attacks in which hidden instructions are used to extract sensitive information from the AI context.
  • Manipulation of the AI’s behavior: Attempts to trick the AI into performing unwanted actions.

Prompt Shield integrates with Azure AI Content Safety to classify and filter unsafe content, and can be applied to user groups at a granular level through security profiles and conditional access policies. OWASP lists prompt injection as LLM01:2025 – in other words, the most critical risk for LLM-based applications.

6. Web content filtering and threat intelligence

In addition to AI-specific protection, Internet Access offers comprehensive filtering of web content by category (e.g., social media, gambling, malware pages) as well as threat intelligence filtering, which blocks traffic to known malware domains, phishing sites, and command-and-control infrastructures – for all users, regardless of their location.

The architecture: How Internet Access controls shadow AI

User (GSA client)

    │

    ▼

Global Secure Access Edge

    │

    ├── TLS inspection (decrypting/inspecting/encrypting)

    │

    ├── Shadow AI Discovery (detection & risk scoring)

    │

    ├── Prompt Shield (real-time prompt inspection)

    │

    ├── Web content filtering / threat intelligence

    │

    └── Conditional access policy enforcement

           │

           ├── Approved: Access allowed

           └── Blocked: Access denied + log entry

All checks are performed at the network level and are therefore independent of the browser used or the device’s status. The GSA client on the end device (Windows, macOS, iOS, Android) ensures that data traffic is routed through GSA Edge.

Summary: AI security starts in your own network

Shadow AI is not a theoretical threat – it is a reality in nearly every company. The solution does not lie in a blanket ban on AI – which would fail in practice anyway – but rather in controlled visibility and sophisticated management.

Microsoft Entra Internet Access, as part of Global Secure Access, offers exactly this: an identity-driven, network-based layer of protection that doesn’t prevent the use of AI, but makes it secure. From detecting unauthorized tools to granular access controls and real-time protection against prompt injection, Internet Access is the central component of a modern AI security strategy.

Licensing (overview, as of May 2026)

  • Microsoft Entra ID P1/P2: Prerequisite: enables basic GSA functions (M365 profile, Compliant Network Check)
  • Standalone Internet Access: approx. $5 per user per month (in addition to P1/P2)
  • Entra Suite: approx. $12 per user per month – includes Private Access, Internet Access, Entra ID Governance, ID Protection (P2), and Verified ID Premium
  • Microsoft 365 E7 (GA as of May 2026): first M365 SKU to include the full Entra Suite