AI inventory

ChatGPT

OpenAI · Assistant · Confirmed · catalog openai-chatgpt. Seen by 10 lanes through 11 findings.

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Combined score
100
Critical 85 from the strongest lane + 15 for 9 more
People
19
Tenant-wide admin consent
Seen by
10
Entra consent, Source code, Purview DLP, SIEM, Azure & Power Platform, Vendor account, Email, Network, Endpoint, Identity
First seen
Aug 10, 2025
Last seen 3 h ago
active-7dadmin-consent-auditedsource-codefixturehardcoded-keyspublic-exposurecorroborateddlphigh-impact-datanot-blockeduser-overridesdlp-blockedsiemheavy-uploadpower-platformthird-party-connectordefault-environmentvendoropenaisanctioned-accountexternal-membersstale-keysservice-accountsadmin-heavycost-growthsanctionedemail-signalnew-accountspaid-on-work-emailnetworkendpointidentityoktaadmin-managedgoogleworkspaceuser-consenteddormant
Evidence

Where it was seen

Strongest finding →
Entra consent
Critical85

tenant-wide consent, 26 sign-ins

Consent
Tenant-wide
Permission tier
High
Sign-ins 30d
26
Data reach
Directory, Email, Files & sites
all users · 3 d agoOpen finding →
Source codeGitHub (demo)
Critical81

4 repos, 3 packages, 2 keys

Repos
4
Packages
3
Keys in code
2
Public repos
1
0 people · 27 h agoOpen finding →
Purview DLP
ChatGPT: sensitive data
High70

5 DLP events, 4 not blocked

Events
5
Not blocked
4
Blocked
1
Top types
All Full Names, U.S. Social Security Number (SSN)
3 people · 3 d agoOpen finding →
SIEMSplunk (demo)
High66

21007 events, 505 MB up via Splunk (demo)

Events
21007
Uploaded
505 MB
Users
3
Sources
5
3 people · 3 h agoOpen finding →
Azure & Power Platform
ChatGPT via Power Platform
High60

3 connections in 1 env

Connections
3
Environments
1
Makers
3
Data path
Third party
3 people · 5 d agoOpen finding →
Vendor accountOpenAI (demo)
High59

11 seats, 2 external, 4 keys, 4360 USD via OpenAI (demo)

Seats
11
External
2
API keys
4
Spend 30d
$4,360
11 people · 25 h agoOpen finding →
Email
High58

3 signups, 2 billing emails

Signups
3
Billing emails
2
Recipients
4
Messages
7
4 people · 20 h agoOpen finding →
Network
High51

11 users, 50 MB up

Users
11
Uploaded
50 MB
Transactions
5110
Defender score
7/10
11 people · 3 h agoOpen finding →
Endpoint
Medium48

2 devices, 2 accounts

Devices
2
Accounts
2
Processes
1
Extensions
0
2 people · 6 h agoOpen finding →
IdentityOkta (demo)
Medium38

10 assigned, 60 sign-ins via Okta (demo)

Assigned
10
Sign-ins
60
OAuth grants
0
Scope tier
Unknown
10 people · 3 h agoOpen finding →
IdentityGoogle Workspace (demo)
Medium30

0 sign-ins, 5 OAuth grants via Google Workspace (demo)

Assigned
0
Sign-ins
0
OAuth grants
5
Scope tier
Low
5 people · 29 d agoOpen finding →
Next steps

Recommended actions

  1. 01
    ChatGPT trains on data unless a business tier or opt-out is used. Verify which tier these users are on.
    Entra consentSource codePurview DLPSIEMVendor accountEmailNetworkEndpointIdentity
  2. 02
    Adoption is broad enough that outright blocking will disrupt work. Prefer a sanctioned alternative plus Conditional Access.
    Entra consentNetworkIdentity
  3. 03
    ChatGPT has tenant-wide admin consent. Confirm a documented approval exists, or revoke the grant and require per-user consent.
    Entra consent
  4. 04
    Scopes expose directory, email, files. Evaluate the vendor's retention and training terms before allowing continued use.
    Entra consent
  5. 05
    4 people signed in during the last 30 days under the tenant-wide consent. Start the conversation with them.
    Entra consent
  6. 06
    2 keys for ChatGPT are in source control, including a public repository. Rotate them now, move to a secret manager, and turn on push protection so it cannot happen again.
    Source code
  7. 07
    ChatGPT SDKs appear in 4 repositories. Decide whether this vendor is approved for engineering, and route calls through one gateway or an Azure OpenAI deployment so keys, logging, and data terms are managed centrally.
    Source code
  8. 08
    Direct HTTP calls to api.openai.com bypass any SDK-level controls. Add the hosts to egress policy and prefer the sanctioned client library.
    Source code
  9. 09
    4 of 5 matches were not blocked (All Full Names, U.S. Social Security Number (SSN), Credit Card Number). Review which rules still run in audit mode and align them with the blocking rules.
    Purview DLP
  10. 10
    1 person overrode the DLP warning. Read the business justifications in Activity explorer; repeated overrides for the same data type mean the policy is wrong or the training is.
    Purview DLP
  11. 11
    High-impact information types were involved (All Full Names, U.S. Social Security Number (SSN), Credit Card Number). Treat this as a data incident: confirm with the user what was pasted, and check the vendor's retention terms for the accounts involved.
    Purview DLP
  12. 12
    505 MB left for ChatGPT through Splunk (demo) in 30 days. Check the proxy or firewall for file uploads and pair this with a DLP rule for AI destinations.
    SIEM
  13. 13
    Splunk (demo) confirms what Microsoft 365 signals show for ChatGPT. Use the source list here to find the exact devices and network segments involved.
    SIEM
  14. 14
    ChatGPT via Power Platform trains on data unless a business tier or opt-out is used. Verify which tier these users are on.
    Azure & Power Platform
  15. 15
    OpenAI (Independent Publisher) sends flow and app data to a third-party AI API. Classify the connector as Blocked or Business in a Power Platform DLP policy so it cannot be combined with SharePoint, Dataverse, or Outlook connectors.
    Azure & Power Platform
  16. 16
    Connections exist in the Default environment, where every licensed user is a maker. Move sanctioned AI work to a managed environment and apply a DLP policy to Default.
    Azure & Power Platform
  17. 17
    2 seats belong to addresses outside the company in the OpenAI organization. Remove them or move the account to SSO with domain verification so only directory identities can hold a seat.
    Vendor account
  18. 18
    2 API keys have not been used in 90 days or never at all. Revoke them; a key that is not used is only a liability.
    Vendor account
  19. 19
    5 of 11 members are owners or admins. Keep admin to two or three named people and use workspace roles for everyone else.
    Vendor account
  20. 20
    Spend grew 51% to 4,360 USD in 30 days. Set a monthly budget alert on the vendor side and per-workspace limits where the vendor supports them.
    Vendor account
  21. 21
    1 key is held by service accounts. Confirm each maps to a production system with an owner, and rotate on a schedule.
    Vendor account
  22. 22
    With 11 members, manage seats through SCIM or the directory rather than by hand, and mirror the member list against leavers monthly.
    Vendor account
  23. 23
    3 signup emails show people creating ChatGPT accounts with their work address. Those accounts live outside Entra, so leaving the company does not close them. Move users to the enterprise tier with SSO, or add a mail flow rule that flags vendor signups to the security team.
    Email
  24. 24
    2 billing emails mean someone is paying for ChatGPT personally and expensing or absorbing it. Consolidate onto a company license where data terms are negotiated.
    Email
  25. 25
    50 MB uploaded to ChatGPT in 30 days from 11 people. Check what data is leaving with Defender's file and session policies.
    Network
  26. 26
    ChatGPT is corroborated by an Entra consent grant. Review both findings together; the consent finding shows what data the app can read.
    Network
  27. 27
    ChatGPT is installed as a desktop app on 2 devices. If it is not approved, block it with App Control for Business or an attack surface reduction rule, and deploy the sanctioned alternative through Intune.
    Endpoint
  28. 28
    Device telemetry names the exact machines and accounts reaching chatgpt.com, api.openai.com. Use it to target coaching rather than blanket blocks.
    Endpoint
  29. 29
    ChatGPT is assigned through Okta, so it already has an owner. Confirm the assignment group is deliberate and mark the app sanctioned here if it is.
    Identity
  30. 30
    ChatGPT holds low-scope OAuth grants from 5 people (sign-in only). Low exposure, but decide whether "Sign in with Google" to AI apps is allowed at all.
    Identity
  31. 31
    ChatGPT was connected by users, not assigned by an admin. If it is approved, add it to the Workspace app catalog so access is managed and can be revoked at offboarding.
    Identity
  32. 32
    Nobody signed into ChatGPT through Google in 90 days. Unassign or revoke to reduce standing access.
    Identity
Who

People

An administrator consented on behalf of all users. Every account in the tenant can use this app without granting anything themselves.
PersonDepartmentSourcesSeen bySign-ins · 30 d
Dave Patel
n/a
Sign-in onlyAudit logSIEM logsVendor seatVendor emailNetwork trafficDevice telemetryIdentity provider
Entra consent · Purview DLP · SIEM · Vendor account · Email · Network · Endpoint · Identity12 · 4 d ago
Alice Ng
n/a
Sign-in onlySIEM logsVendor seatNetwork trafficDevice telemetryIdentity provider
Entra consent · SIEM · Vendor account · Network · Endpoint · Identity2 · 16 d ago
Erin Walsh
n/a
Sign-in onlyAudit logVendor seatNetwork trafficIdentity provider
Entra consent · Purview DLP · Vendor account · Network · Identity8 · 3 d ago
n/a
Audit logPlatform owner or makerVendor emailNetwork trafficIdentity provider
Purview DLP · Azure & Power Platform · Email · Network · Identity0
Iris Kim
n/a
Platform owner or makerVendor seatVendor emailNetwork trafficIdentity provider
Azure & Power Platform · Vendor account · Email · Network · Identity0
n/a
Platform owner or makerVendor emailNetwork trafficIdentity provider
Azure & Power Platform · Email · Network · Identity0
Frank Li
n/a
Vendor seatNetwork trafficIdentity provider
Vendor account · Network · Identity0
Grace Hopper
n/a
Vendor seatNetwork trafficIdentity provider
Vendor account · Network · Identity0
Bob Okafor
n/a
Sign-in onlyIdentity provider
Entra consent · Identity4 · 4 d ago
n/a
Identity provider
Identity0
Partner consultant
n/a
Vendor seat
Vendor account0
dave (personal)
n/a
Vendor seat
Vendor account0
n/a
Network traffic
Network0
Mia Chen
n/a
Vendor seat
Vendor account0
Nina Patel
n/a
Vendor seat
Vendor account0
Oscar Ruiz
n/a
Vendor seat
Vendor account0
n/a
Network traffic
Network0
n/a
Network traffic
Network0
svc-datapipeline
svc-datapipeline
n/a
SIEM logs
SIEM0
Vendor

Policy notes

Trains on data
Configurable
Enterprise tier
Available
Org policy
None set

Consumer and Plus train by default with opt-out; Team, Enterprise, and API do not.

Exposure

Data it can reach

DirectoryEmailFiles & sites
Lanes

Score by source

Each lane scores its own evidence. The combined score takes the strongest lane and adds five points per additional lane, capped at 100.