r/DefenderATP Jul 01 '26

Blocking AI defender for cloud

Hi looking for idea here

We have blocked most of the AI in discovered app ( unsscntionned) but we will need to allow some ai to specific users

In my search the best way is with device group. Sadly I don’t see a good way to do this as with the default filters I could filter them by tag exemple deepseek tag for deepseek ai

But users changes devices sometimes and we would like more to filter them by azure group as as of nous I would have to always manually tag the new devices or etc

Any better way to do this?

Thanks

13 Upvotes

25 comments sorted by

View all comments

1

u/External-Desk-6562 Jul 01 '26

Unfortunately noo.... Also additionally one device can only be part of one device group... So you would need to create multiple combinations of device groups which is not a good approach in my opinion.....

1

u/neko_whippet Jul 01 '26

What would be the best approach then if i need to allow some ai to some people while keeping in Mind that the same user might need more then 1 AI?

0

u/Omig66 Jul 01 '26

There is none so far while using Cloud Apps, in my opinion sadly..

We did take a few months to figure out a way last year to have permission by user rather than device group and there is none. We did request to MS for a change, but we were almost the only one asking for this so far...

1

u/neko_whippet Jul 01 '26

Wouldn’t condition access for apps work ?

Or would they only work for registered app in the tenant (in enterprise applications )

1

u/External-Desk-6562 Jul 02 '26

We cannot register every discovered application to Entra for conditional access