Sessions Hero

ESPC26
Conference Sessions

Security, Compliance, and Governance Info

Shadow AI: Find It. Control It.

Engineering & Operations Info
Level 300 Info

SPEAKERS

Aasne Holtklimpen

MVP
Crayon (merging with SoftwareOne)

ABOUT THE SESSION

Your users bypassed your Copilot restrictions before lunch on day one. They’re already using Shadow AI, unapproved LLMs, browser-based PDF analyzers, and whatever tool TikTok recommended this week. Blocking them kills productivity; ignoring them creates a data leak buffet.

This session gives you the tactical patterns for Safe AI Adoption in the real world. We’ll show how to use Defender for Cloud Apps to expose Shadow AI usage, how Endpoint DLP can sanitize sensitive data before it leaves the device, and how to govern “Bring Your Own Model” scenarios in Azure without becoming the Department of No.

Shadow AI isn’t going away. Time to stop fighting the tide and start engineering the dam.

Assumed Knowledge:

Working familiarity with the Microsoft Security Stack (Defender, Endpoint DLP). Basic understanding of Azure architecture and governance. Foundational knowledge of LLMs and why Shadow AI creates data-leak risks.

Practical Takeaways:

Visibility: How to use Defender for Cloud Apps to detect and map unapproved AI usage across your environment. Data Protection: Configuring Endpoint DLP to sanitize sensitive data before it hits external AI models. Governance: Architectural patterns for managing “Bring Your Own Model” scenarios in Azure without blocking innovation.

Out of Session Scope:

Model development, training, or fine-tuning (Python, PyTorch, etc.). Prompt engineering or end-user productivity coaching. Non-Microsoft security tools or third-party DLP solutions.

MEET THE SPEAKERS

Aasne Holtklimpen

Aasne Holtklimpen

MVP

Crayon (merging with SoftwareOne)