Join our Newsletter — 33% off our NHI Course

Unmanaged SaaS and AI tools outside SSO: are controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Shadow IT is no longer just an app sprawl problem: 52% of employees have downloaded apps without IT approval, and unmanaged SaaS and AI tools can create authenticated access paths that traditional IAM monitoring misses, according to 1Password. The governance issue is not discovery alone, but whether teams can see, review, and revoke non-SSO access before it becomes standing privilege.

Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “The unmanaged stack: Governing SaaS apps and AI tools outside SSO”.

By the numbers:

  • 52% of employees have downloaded apps without IT approval, according to 1Password.

Key questions

Q: What breaks when SaaS apps are used outside SSO and central IAM?

A: The main failure is lifecycle control.

Q: Why do OAuth connections create governance risk even when logins are valid?

A: OAuth connections create governance risk because they grant durable delegated access that can remain active long after the initial approval.

Practitioner guidance

  • Map non-SSO access paths Inventory SaaS apps, AI tools, OAuth grants, and shared logins that exist outside the identity provider so you can see where governance is missing.
  • Review delegated OAuth scopes Check each third-party connection for scope, business owner, and continued need, then remove grants that no longer match current use.
  • Assign ownership for unmanaged accounts Move sensitive or shared credentials into IT-owned governance so responsibility for review, access changes, and revocation is explicit.

Bottom line: Unmanaged SaaS and AI tools outside SSO create identity risk because access can be valid, delegated, and still outside central governance.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 6 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21474
 

Non-SSO access is now a parallel identity estate: Once SaaS and AI tools are provisioned outside SSO, they stop behaving like ordinary app usage and start behaving like governed identities with their own ownership, lifecycle, and privilege history. Traditional IAM coverage does not automatically extend into that estate, so visibility has to be built around access pathways, not application lists. Practitioners should treat unmanaged tools as part of the identity control plane, not as a separate IT cleanup issue.

A few things that frame the scale:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

A question worth separating out:

Q: What should teams do when shadow SaaS is discovered in a business unit?

A: Contain the risk by identifying the user, the data stored, and the business purpose, then decide whether to approve, migrate, or block the service. If the application is kept, it needs ownership, review cadence, and offboarding rules. If it is blocked, data removal must be verified.

👉 Read our full editorial: SaaS and AI tools outside SSO expose unmanaged identity risk


This post was modified 6 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.