AI Agents - Orphaned Agents with Disabled Owners

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query identifies AI agents whose owners are all either disabled or removed from the organization. Orphaned agents without an active owner pose governance and security risks because no one is accountable for their configuration, updates, or potential misuse. If these agents remain active, they could retain sensitive connections or perform actions without proper oversight, increasing the risk of unauthorized access or persistence in the environment. Recommended Action: Assign a new active own

Attribute Value
Type Hunting Query
Solution GitHub Only
ID 47ea3b0e-bedd-4fde-bda9-86aa76684a9b
Tactics Persistence, DefenseEvasion
Techniques T1078, T1562
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/AI%20Agents/AgentsInfoOrphanedAgents.yaml)

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
IdentityInfo ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries