Generative AI
ChatGPT, Claude, Gemini
- Shadow AI usage
- Sensitive data leakage
- Compliance gaps
Microsoft 365 Copilot
Word, Excel, Teams
- Data exposure
- Insider misuse
- Auditability gaps
Custom AI agents
Copilot Studio, Bot Framework
- Prompt injection
- Unauthorized data access
- Policy non‑adherence
Local LLMs
Llama, Mistral, self‑hosted GPT
- Model tampering/poisoning
- Infrastructure vulnerabilities
- Data exfiltration
AI development tools
GitHub Copilot, VS Code
- Insecure code suggestions
- Secrets in code
- Dependency risk
AI‑powered business apps
Power Platform, custom apps
- Sensitive data exposure
- Citizen dev sprawl
- Policy violations
Multi‑cloud AI
AWS Bedrock, GCP Vertex AI
- Inconsistent controls
- Over‑permissioned APIs
- Fragmented monitoring
Edge & IoT AI
Smart cameras, robotics, vehicles
- Adversarial inputs
- Device compromise
- Safety failures
AI in security operations
Security Copilot, anomaly detection
- False positives/negatives
- Model drift
- Adversarial evasion
Data & analytics (RAG)
Enterprise knowledge bots
- Sensitive data retrieval
- Hallucinated citations
- Source poisoning
Creative & media AI
Image/video gen, synthetic voice
- IP misuse
- Deepfake risks
- Authenticity gaps
Industry‑specific AI
Healthcare, finance, manufacturing
- Regulatory compliance
- Safety‑critical accuracy
- Domain data leakage
AI supply chain & lifecycle
Model marketplaces, embeddings, OSS weights
- Poisoned datasets
- Malicious model updates
- Dependency tampering
AI governance & compliance
Responsible AI, audit trails, policies
- Explainability gaps
- Accountability issues
- Regulatory misalignment
View: Microsoft
| Domain â–¼ / Product â–¶ | Defender for Cloud Apps | Purview IP/DLP | Purview Endpoint DLP | Purview DSPM for AI | Entra Conditional Access | Sentinel | Security Copilot | Insider Risk Mgmt | Defender for Cloud | Defender for Endpoint | Defender for DevOps | Defender for Containers | Azure AI Content Safety | Power Platform Admin | Compliance Manager |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Generative AI | â— | â— | â— | â— | â— | â— | â— | â— | â—‹ | â—‹ | â—‹ | â—‹ | â— | â—‹ | â— |
| M365 Copilot | â— | â— | â— | â— | â— | â— | â— | â— | â—‹ | â—‹ | â—‹ | â—‹ | â— | â—‹ | â— |
| Custom agents | â— | â— | â— | â— | â— | â— | â— | â—‹ | â— | â—‹ | â—‹ | â—‹ | â— | â—‹ | â— |
| Local LLMs | â—‹ | â— | â— | â— | â— | â— | â—‹ | â—‹ | â— | â— | â— | â— | â— | â—‹ | â— |
| AI dev tools | â—‹ | â—‹ | â— | â— | â— | â— | â—‹ | â—‹ | â— | â— | â— | â— | â—‹ | â—‹ | â— |
| Business apps | â— | â— | â— | â— | â— | â— | â—‹ | â— | â—‹ | â—‹ | â— | â—‹ | â—‹ | â— | â— |
| Multi‑cloud AI | ◠| ○ | ◠| ◠| ◠| ◠| ◠| ○ | ◠| ○ | ○ | ◠| ○ | ○ | ○ |
| Edge & IoT AI | â—‹ | â— | â— | â— | â— | â— | â—‹ | â—‹ | â— | â— | â—‹ | â—‹ | â—‹ | â—‹ | â—‹ |
| SecOps AI | â—‹ | â—‹ | â— | â— | â— | â— | â— | â—‹ | â—‹ | â—‹ | â—‹ | â—‹ | â— | â—‹ | â—‹ |
| Data & RAG | â— | â— | â— | â— | â— | â— | â—‹ | â—‹ | â—‹ | â—‹ | â—‹ | â—‹ | â— | â—‹ | â— |
| Creative & media | â— | â— | â— | â— | â— | â— | â—‹ | â— | â—‹ | â—‹ | â—‹ | â—‹ | â— | â—‹ | â—‹ |
| Industry AI | â— | â— | â— | â— | â— | â— | â— | â— | â— | â—‹ | â—‹ | â—‹ | â—‹ | â— | â— |
| Supply chain & lifecycle | â—‹ | â— | â— | â— | â—‹ | â— | â—‹ | â—‹ | â— | â— | â— | â— | â—‹ | â—‹ | â— |
| Governance & compliance | â— | â— | â— | â— | â— | â— | â— | â— | â— | â—‹ | â—‹ | â—‹ | â— | â— | â— |
Legend:
â— Prevention
â— Detection
â—‹ Discovery / Not applicable