AI inventory

Azure OpenAI

Microsoft · Cloud AI platform · Confirmed · catalog azure-openai. Seen by 2 lanes through 4 findings.

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Combined score
60
High 55 from the strongest lane + 5 for 1 more
People
3
Distinct identities across every lane
Seen by
2
Azure & Power Platform, Source code
First seen
May 17, 2026
Last seen 6 d ago
azurefirst-partypublic-endpointkey-authno-owner-tagmodel-deploymentspower-platformsource-codefixturecorroborated
Evidence

Where it was seen

Strongest finding →
Azure & Power Platform
Azure OpenAI: dave-openai-test
High55

accounts in rg-sandbox-dave, public

Type
accounts
Network
Public
Key auth
Enabled
Deployments
1
Azure & Power Platform
Azure OpenAI: aoai-prod-eastus
Medium30

accounts in rg-ai-prod

Type
accounts
Network
Private
Key auth
Disabled
Deployments
2
Azure & Power Platform
Azure OpenAI via Power Platform
Medium30

3 connections in 2 envs

Connections
3
Environments
2
Makers
3
Data path
Microsoft
3 people · 15 d agoOpen finding →
Source codeGitHub (demo)
Medium26

1 repo, 1 packages

Repos
1
Packages
1
Keys in code
0
Public repos
0
0 people · 6 d agoOpen finding →
Next steps

Recommended actions

  1. 01
    'Azure OpenAI: dave-openai-test' accepts traffic from any network. Put it behind a private endpoint or restrict network ACLs to your VNet and office ranges.
    Azure & Power Platform
  2. 02
    API key authentication is enabled. Disable local auth and use managed identities with Cognitive Services roles so a leaked key cannot be replayed.
    Azure & Power Platform
  3. 03
    No owner tag. Tag the resource with an owner and cost center so someone answers for its prompts, spend, and content-filter settings.
    Azure & Power Platform
  4. 04
    1 model deployment (gpt-4.1). Confirm content filtering and abuse monitoring are on, and that logging captures prompts if your policy requires it.
    Azure & Power Platform
  5. 05
    2 model deployments (gpt-4o, text-embedding-3-large). Confirm content filtering and abuse monitoring are on, and that logging captures prompts if your policy requires it.
    Azure & Power Platform
  6. 06
    Azure OpenAI keeps data inside Microsoft, so the question is governance: confirm the 3 makers are expected and the flows are owned by a team, not an individual.
    Azure & Power Platform
  7. 07
    Azure OpenAI SDKs appear in 1 repository. Decide whether this vendor is approved for engineering, and route calls through one gateway or an Azure OpenAI deployment so keys, logging, and data terms are managed centrally.
    Source code
Who

People

PersonDepartmentSourcesSeen bySign-ins · 30 d
n/a
Platform owner or maker
Azure & Power Platform0
n/a
Platform owner or maker
Azure & Power Platform0
n/a
Platform owner or maker
Azure & Power Platform0
Vendor

Policy notes

Trains on data
No
Enterprise tier
Available
Org policy
None set

Enterprise-grade OpenAI models inside the customer's Azure boundary; risk is misconfiguration, not the vendor.

Billing

What it costs

Last 30 days
$2,665
Previous 30
$1,733
Lanes

Score by source

Each lane scores its own evidence. The combined score takes the strongest lane and adds five points per additional lane, capped at 100.