Coverage & prerequisites
What AI Pulse can see, and what it needs to see it.
On Azure, AI Pulse governs Microsoft AI estates. Its discovery coverage follows the Microsoft surfaces and licences you already run — no agents to install, nothing to write.
01Surfaces
The Microsoft estate, mapped
Discovery spans the places Microsoft AI actually lives: Azure AI Foundry and Azure OpenAI deployments, Copilot Studio agents, Microsoft 365 Copilot usage, Power Platform, Fabric, and custom applications built on Microsoft AI SDKs — plus the cost signals that betray what nobody registered.
Estates beyond Microsoft — other clouds, self-hosted models — are reached by deploying the enforcement layer, which runs anywhere. We would rather tell you where the Azure-native sight ends than pretend it doesn't.
02Prerequisites
What you need before day one
| Requirement | Detail |
|---|---|
| Azure subscription | An active Azure subscription in your own tenant; AI Pulse deploys as a managed application directly into it. |
| Permissions | A read-only managed identity is created at deployment. No write permissions exist in the permission set — nothing to grant or revoke. |
| Identity | Microsoft Entra ID for your users, with MFA enforced by your own conditional access policies. |
| Microsoft 365 / Copilot surfaces | Discovery of Copilot and Power Platform AI usage draws on Microsoft Graph and related management APIs; coverage scales with the licences you already hold. |
| Cost Management | Cost signals help surface shadow AI — unregistered spend is often the first trace of an unregistered system. |
03Where sight ends
The agents a network-based view cannot reach
Discovery reads the management surfaces: Resource Graph for what is deployed, Microsoft Graph and the related management APIs for Copilot and Power Platform usage, and cost signals for the spend that betrays an unregistered system.
That reaches everything running in your estate. It does not reach an agent whose model call happens entirely inside a vendor's own cloud — Copilot Studio agents, Salesforce Agentforce and similar. By agent count that class is substantial at many enterprises, and no network-based view can see into it, however well built.
For those, visibility comes from whatever the vendor's own audit trail records: typically who ran the agent and when, sometimes a summary of what it touched — never prompt content, never tool-call intent, and no ability to stop anything. We name that class separately rather than folding it into a coverage number, because a governance tool that quietly counts what it cannot see is worse than one that admits the gap.
Honest boundaries
- In your estateFull discovery
- Vendor-cloud agentsAudit log only
- Non-Microsoft cloudsVia enforcement
- Enforcement thereNot possible
Coverage is verified against your own estate during evaluation, so none of this is left as a surprise.
Exact licence-tier coverage depends on the Microsoft licences in your tenant. We verify coverage against your estate during evaluation — before you buy anything.