By NHI Mgmt Group Editorial TeamBased on JumpCloud: “Standardize, Automate, Govern” (August 20, 2025)

TL;DR: MSPs are operating across Windows, Google Workspace, mobile, SaaS, and near-universal AI adoption, and JumpCloud says high-growth firms are responding with standardised policies, automation, and strict shadow IT enforcement. The security lesson is that sprawl is now the operating baseline, so governance must scale across devices, apps, and AI access together.


At a glance

What this is: This is a JumpCloud analysis of MSP operations showing that device, SaaS, and AI sprawl has become the normal operating baseline rather than an edge case.

Why it matters: It matters because MSP governance now has to cover heterogeneous access, unmanaged applications, and AI usage together, or security policy becomes inconsistent across client environments.

By the numbers:

  • 70% of MSPs are managing more than just Windows environments.
  • 64% of organizations are running both Microsoft and Google Workspace.
  • AI adoption has skyrocketed to nearly 100%.

Context

MSP governance now spans a mixed estate of endpoints, SaaS applications, cloud services, mobile devices, and AI usage. The security problem is not a single control failure but the mismatch between fragmented environments and policies that were designed for a much narrower stack.

JumpCloud's article argues that high-growth MSPs are not trying to simplify the environment first. They are standardising policy, automating routine management, and enforcing shadow IT controls so that service delivery stays consistent as client sprawl increases.


Key questions

Q: How should MSPs govern device, SaaS, and AI sprawl across client environments?

A: MSPs should govern sprawl with one baseline policy model, then apply client-specific exceptions in a controlled way. The practical goal is to keep device, application, and AI access decisions consistent across tenants, so security does not depend on manual judgement or one-off administration.

Q: Why do mixed device and SaaS estates create governance risk for MSPs?

A: Mixed estates create governance risk because controls, approval paths, and update practices drift when each platform is managed differently. The result is uneven enforcement, inconsistent visibility, and a growing gap between policy intent and what is actually happening across client environments.

Q: What breaks when MSPs try to manage shadow IT manually?

A: Manual shadow IT handling breaks when discovery, approval, and enforcement cannot keep pace with SaaS and AI adoption. Unmanaged tools continue to appear, business users keep adopting them, and the MSP ends up reacting after access has already spread beyond the approved stack.

Q: How can MSPs tell whether their governance model is actually working?

A: A governance model is working when the same policy requirements are being enforced consistently across devices, applications, and AI usage without excessive exception handling. If every client needs a different control path to achieve the same outcome, the model is not scalable.


Technical breakdown

Why mixed device and SaaS estates break manual governance

A mixed estate becomes hard to govern when access rules, patching, application approvals, and security exceptions are all handled per client or per platform. That creates uneven control coverage and makes it difficult to prove that baseline requirements are being applied consistently. In MSP terms, the challenge is not just technical complexity. It is the operational drift that appears when Windows, Google Workspace, mobile devices, and cloud services are managed as separate problems instead of one governance surface.

Practical implication: Use one policy baseline for device, SaaS, and cloud access governance, then map client-specific exceptions explicitly.

How automation changes MSP security operations

Automation reduces the number of manual touchpoints where configuration drift, missed updates, and inconsistent enforcement are introduced. For MSPs, that matters because every extra manual step multiplies across clients and environments. Automation does not remove the need for governance. It makes the governance repeatable, so routine actions such as enrollment, updates, and security enforcement are applied at scale without depending on technician memory or ad hoc escalation paths.

Practical implication: Automate repeatable device and access tasks first, then reserve human handling for exceptions and high-risk decisions.

Shadow IT and AI sprawl as a governance problem

Shadow IT becomes more difficult when SaaS usage and AI adoption are both widespread, because unmanaged tools can enter the environment through ordinary business workflows. The issue is not only discovery. It is lifecycle control over what gets approved, who can use it, and whether it remains visible to the MSP after initial adoption. Once AI tools are part of everyday work, unmanaged access becomes a governance and assurance problem, not just an application inventory gap.

Practical implication: Tie application approval, visibility, and revocation to the same governance process for SaaS and AI tools.


NHI Mgmt Group analysis

Device, SaaS, and AI sprawl is now a governance baseline, not an exception: MSPs are no longer managing a clean endpoint estate with a few predictable applications on top. They are managing heterogeneous access surfaces that change by client, platform, and user behaviour, which means the old model of platform-by-platform administration no longer holds. The practitioner implication is that governance has to be designed for fragmentation from the start.

Standardisation is the control plane for scale: High-growth MSPs are not winning by treating every client as a bespoke security design exercise. They are winning by enforcing one policy framework across devices and services, then allowing only explicit exceptions. That is the only way to keep operational overhead from growing faster than revenue. Practitioners should treat policy consistency as a service quality issue, not just a security one.

Automation is what turns governance into an MSP operating model: Manual enforcement does not scale when mobile, SaaS, and AI usage are all rising together. Automation reduces drift, but its real value is that it makes enforcement repeatable across tenants and clients. The result is less variance in baseline controls and less dependence on technician discretion.

Shadow AI governance gap: The control assumption that approved software lists capture most user access no longer holds when AI adoption is nearly universal and new tools can appear outside central review. That assumption fails because AI use now enters through everyday productivity workflows, not only formal procurement. The implication is that visibility and enforcement must move closer to usage and approval pathways.

MSP governance is converging on lifecycle control, not point-in-time control: The article points toward a market where access, device posture, SaaS approval, and AI usage are governed as a continuous lifecycle. That aligns with broader identity governance principles across human and non-human access. Practitioners should expect the strongest programmes to measure consistency of control application rather than count isolated policy wins.

What this signals

Shadow AI governance gap: MSPs need a visibility model that treats AI usage as part of the same control surface as SaaS and device access, because unmanaged tools now enter through normal work patterns rather than special projects. That shifts the problem from inventory alone to approval, enforcement, and offboarding across the full access lifecycle.

The operational signal for practitioners is simple: if security policy cannot be applied consistently across Windows, mobile, SaaS, and AI-enabled workflows, the programme is already fragmenting. The strongest MSPs will be the ones that reduce variance in enforcement, not the ones that promise perfect uniformity.


For practitioners

  • Standardise client baseline policies Define one enforceable security baseline for devices, SaaS approvals, and access settings, then document exceptions separately for each client.
  • Automate routine governance tasks Use automation for patching, enrollment, security updates, and recurring policy enforcement so technicians spend less time on repetitive work.
  • Create a shadow IT enforcement process Set a process for identifying unsanctioned SaaS and AI tools, validating business need, and removing access when they are not approved.
  • Track policy adherence across tenants Measure whether the same control requirements are being applied across Windows, mobile, SaaS, and AI-enabled workflows for every client.

Key takeaways

  • MSP security governance is no longer about a single endpoint stack. It now has to absorb device diversity, SaaS sprawl, and AI usage as part of the normal operating model.
  • The article's core evidence is that high-growth MSPs respond with standardised policies, automation, and strict shadow IT enforcement rather than ad hoc manual control.
  • Practitioners should focus on consistent baseline enforcement across tenants, because operational scale depends on reducing variance in policy application.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP API Security Top 10 addresses the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementMSP governance depends on consistent account and access administration across clients.
Recommendation — Apply CIS-5 to standardise account lifecycle controls across every managed tenant.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about enforcing consistent access decisions across devices, SaaS, and AI usage.
Recommendation — Use PR.AA-05 to align entitlement enforcement across all client environments.
NIST Zero Trust (SP 800-207)5.2 — Policy Enforcement PointThe article centres on applying uniform control enforcement across fragmented environments.
Recommendation — Map governance decisions to policy enforcement points so access is checked consistently at use time.
OWASP API Security Top 10API9 — Improper Inventory ManagementShadow SaaS and AI sprawl create inventory gaps that weaken visibility and control.
Recommendation — Inventory all sanctioned SaaS and AI tools so unmanaged access paths do not accumulate.

Key terms

  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
  • Policy Baseline: A policy baseline is the vendor or organisation's expected security state for a setting, rule, or configuration. It proves alignment with a standard, but not whether the control meaningfully reduces risk in production or disrupts attacker behaviour.
  • Automation at Scale: Automation at scale is the use of repeatable workflows to apply security and administrative actions across many environments with low manual effort. In MSP governance, it reduces variance, limits human error, and makes control enforcement practical across large multi-tenant estates.
  • Governance Sprawl: Governance sprawl is the condition where policy, approval, and enforcement paths become fragmented across too many platforms, clients, or exceptions. It usually shows up when growth outpaces standardisation, leaving teams with inconsistent oversight and uneven control application.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org