Skip to content
This is NOT an official site of the Government of Canada. Click here for the official AI registry.

AI-Powered Endpoint and Identity Threat Detection

Safety & Security

What it collects that can identify you

Sensitive personal information
Identifiable data
  • Active Directory signals and Entra ID client certificate checks that link device and cloud activity to specific GC employee identities.

Canada AI Register — 2526-CSPS-EFPC-022

About behaviour
Pseudonymous data
  • Endpoint telemetry capturing device activity patterns — process execution, network connections, file operations — used to identify suspicious behavioral sequences.

Canada AI Register — 2526-CSPS-EFPC-022

Run by
Canada School of Public Service (CSPS)
Where
No fixed location
Kept
Not stated by the Helpful Places.
Shared with
Accountable organization, Vendor
Your copy
You cannot see the data it holds about you. What you can do

What it is for

This system monitors Government of Canada employees' work devices, identity accounts, and cloud application usage to detect cybersecurity threats using artificial intelligence. It analyzes behavioral patterns to identify suspicious activity such as compromised accounts or risky software actions. The system involves personal information about employees, and its use of AI has been disclosed to users. Outputs inform security teams who investigate and respond to alerts.

What it collects and what happens to it

Data taken in

About behaviour
Pseudonymous data
  • Endpoint telemetry capturing device activity patterns — process execution, network connections, file operations — used to identify suspicious behavioral sequences.

Canada AI Register — 2526-CSPS-EFPC-022

Sensitive personal information
Identifiable data
  • Active Directory signals and Entra ID client certificate checks that link device and cloud activity to specific GC employee identities.

Canada AI Register — 2526-CSPS-EFPC-022

Processing

Anomaly Detection
  • Behavioral analytics engine that learns baseline device and identity activity patterns and flags deviations indicating potential compromise or risky cloud app usage.

Canada AI Register — 2526-CSPS-EFPC-022

What it does

Deciding (Analytical AI)
Human decides
  • The system scores and classifies device and identity activity as suspicious or risky, producing alerts that security analysts review and act upon.

Canada AI Register — 2526-CSPS-EFPC-022

Sensing (Perceptive AI)
Autonomous
  • Continuously ingests raw endpoint telemetry, Active Directory signals, and Entra ID certificate data, converting them into structured behavioral signals for downstream analysis.

Canada AI Register — 2526-CSPS-EFPC-022

Outputs

A recommendation or prediction
Identifiable data
  • Security alerts and risk scores surfaced to GC security teams, indicating suspicious device activity, potentially compromised identities, or risky cloud app usage for human review.

Canada AI Register — 2526-CSPS-EFPC-022

Run by

Canada School of Public Service (CSPS)
  • The Canada School of Public Service is the department responsible for deploying and operating Microsoft Defender for Endpoint to protect GC employee devices and identities.

Canada AI Register — 2526-CSPS-EFPC-022

Built by

Microsoft
  • Microsoft is the vendor that builds and licenses the Defender for Endpoint AI system, including its behavioral analytics and threat-detection capabilities.

Canada AI Register — 2526-CSPS-EFPC-022

Kept for

Not stated by the Helpful Places.

Shared with

Available to the accountable organization
  • Security alert data and threat intelligence outputs are available to Canada School of Public Service security staff for incident investigation and response.

Canada AI Register — 2526-CSPS-EFPC-022

Available to vendor
  • As a cloud-delivered service, Microsoft as vendor may have access to telemetry and threat data processed through the platform in accordance with contractual data processing terms.

Canada AI Register — 2526-CSPS-EFPC-022

Not available to me
  • Individual GC employees cannot access the security alerts, behavioral scores, or threat classifications generated about their own devices or accounts through this system.

Canada AI Register — 2526-CSPS-EFPC-022

Stored

Stored on 3rd Party Cloud
  • As a Microsoft cloud-delivered security service, telemetry and threat data are processed and stored on Microsoft's cloud infrastructure.
  • Duration: Not specified in register

Canada AI Register — 2526-CSPS-EFPC-022

How to read the colours

Can it identify you?

Anonymized data
Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
Pseudonymous data
Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
Identifiable data
The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.

Who completes the loop?

Human decides
This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
Human executes
This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
Autonomous
This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.

Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.

What you can do

Ask about this system

Questions go to the Helpful Places, not the vendor.

Your rights

  • Right to Be Informed of AI UseGC employees have been informed that this AI system is in use to monitor endpoint, identity, and cloud application activity for cybersecurity purposes. The register confirms AI use has been disclosed to users.
  • Right to Algorithmic TransparencyEmployees are entitled to understand in plain language that behavioral analytics are used to detect suspicious activity on their work devices and accounts. The Canada School of Public Service is the accountable organization for questions about how the system works.

Risks and safeguards

  • Civil liberties harmContinuous behavioral monitoring of employees raises concerns about workplace surveillance and chilling effects on lawful activity.Safeguard: AI use has been disclosed to users; the system targets cybersecurity threats, not general employee monitoring; outputs are reviewed by human security analysts before action is taken.
  • Reputational harmFalse-positive threat classifications could incorrectly flag a GC employee's account as compromised, leading to account suspension and reputational damage.Safeguard: Security analysts review alerts before consequential action; employees are informed of AI use in the system.