跳到主要內容

Review Generative AI Insights

Implementation Effort: Low

User Impact: Low

Overview

A core Zero Trust principle is to assume breach and continuously monitor activity so you can verify what users, devices, and agents are actually doing. As generative AI adoption grows, organizations need visibility into the prompts sent to AI applications and the Model Context Protocol (MCP) traffic exchanged between AI agents and remote MCP servers. Generative AI Insights in Microsoft Entra Global Secure Access provides a unified surface for reviewing this activity flowing through Internet Access, so you can detect risky usage, discover shadow MCP servers, and correlate AI activity with the user, destination, and transaction behind each event.

Reviewing Generative AI Insights follows these key steps. See the linked documentation for detailed implementation instructions.

  1. Confirm prerequisites — Ensure you have a Global Secure Access license, the Global Secure Access Administrator or Log Reader role, Internet Access traffic forwarding enabled for the users or devices you want to monitor, and TLS inspection enabled (required for prompt logging and for MCP logging on end-user devices).
  2. Open the Generative AI Insights logs page — In the Microsoft Entra admin center, browse to Global Secure Access > Monitor > Generative AI Insights to review GenAI prompt and MCP events, with the most recent events at the top.
  3. Filter and inspect events — Narrow the view by Activity (Prompt or MCP), Sub-activity, Destination URL, or User, then select a row to open the details pane and view the full payload plus the Event, Session, and Transaction IDs used to correlate a request with its response and pivot to the related traffic log.
  4. Discover shadow MCP servers — Set Activity to MCP and review unique Destination URL values to identify previously unknown, private, or shadow MCP servers, then use URL filtering to block traffic to any risky server.
  5. Export and retain — Export the current filtered view (up to 100,000 records) for offline analysis, and stream events to Microsoft Sentinel or Azure Monitor Log Analytics using the NetworkAccessGenerativeAIInsights diagnostic settings category for long-term retention and detection.

Reference