Explore AI inventory in Security Dashboard for AI
Implementation Effort: Low – The AI Inventory page is available at ai.security.microsoft.com with no additional infrastructure deployment; inventory coverage depends on which underlying services (Agent 365, Microsoft Defender, Defender for Cloud Apps) are deployed in the tenant.
User Impact: Low – Security and admin activity only; end users are not affected.
Overview
You cannot secure what you cannot see. Before AI workloads can be governed, risk-assessed, or protected, the organization needs a reliable, up-to-date inventory of every AI asset in the environment — agents, models, MCP servers, and third-party AI applications. Without centralized discovery, AI assets accumulate silently across teams, departments, and cloud subscriptions, creating ungoverned shadow AI that is invisible to security controls and unaccounted for in risk assessments.
The AI Inventory page of the Microsoft Security Dashboard for AI provides this visibility in a single consolidated surface. It organizes discovered assets into three categories: AI agents registered in Microsoft Agent 365, including identity and data sensitivity details sourced from the Entra Agent Registry and Purview DSPM for AI; AI models discovered by Microsoft Defender across Azure environments, including Azure OpenAI and Azure AI Foundry deployments; and MCP servers and other AI applications — including third-party services like Google Gemini and OpenAI ChatGPT — discovered by Microsoft Defender for Cloud Apps. Each asset entry links to the relevant Microsoft Security product for detailed configuration review, risk assessment, and remediation.
Coverage is bounded by deployment: assets not registered in Agent 365 do not appear in the agents tab, and assets not visible to Defender or Defender for Cloud Apps do not appear in the models or applications tabs. This makes the inventory a live signal of both AI asset presence and the gaps in the organization's detection coverage — an incomplete inventory indicates that Agent 365 registration or Defender deployment needs to expand. Filters and export capabilities allow security teams to focus on specific asset types, risk levels, or organizational units for targeted analysis.
This supports Verify explicitly by providing continuous, product-sourced visibility into every AI asset in the environment, ensuring that no deployed model, agent, or AI application operates outside the scope of security governance. It supports Assume breach by making it possible to detect newly deployed or shadow AI assets that have not been registered or reviewed — because ungoverned AI assets are the most likely vector for undetected exploitation. Without this inventory step, the organization's AI security posture is based on incomplete information and reactive discovery rather than continuous, authoritative asset visibility.