Join our Newsletter — 33% off our NHI Course

SaaS sprawl and shadow IT: what IAM teams need to know

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: SaaS-driven shadow IT is expanding as employees adopt apps outside IT oversight, increasing data leakage, compliance exposure, and wasted spend; Zluri says 57% of IT leaders are concerned about shadow IT and 76% of employees prefer working from home. The governance problem is now identity-related as much as procurement-related, because app adoption and access are moving faster than review and control cycles.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “What is Shadow IT? How SaaS Apps are Driving the Next Wave of Shadow IT”.

By the numbers:

  • 57% of IT leaders are concerned about shadow IT, according to Zluri research.
  • 76% of employees say they prefer to work from home, according to Zluri research.

Key questions

Q: What happens when SaaS applications are adopted without IT approval?

A: When SaaS is adopted without IT approval, the organisation accumulates shadow IT, which creates gaps in visibility, policy enforcement, and data protection.

Q: Why does shadow IT become more risky as SaaS adoption and cloud use increase?

A: Shadow IT becomes riskier as SaaS and cloud usage grow because procurement, configuration, and access controls spread across more teams and more endpoints.

Q: How can security teams tell whether SaaS chaos is still generating sprawl?

A: Look for a widening gap between the official application inventory and what multi-source discovery reveals in practice.

Practitioner guidance

  • Implement continuous SaaS discovery Reconcile SaaS usage from expense data, SSO logs, browser telemetry, and cloud app connectors to build a live app inventory.
  • Govern employee-purchased apps centrally Require business-owned apps to meet the same vetting, access ownership, and offboarding requirements as IT-managed applications.
  • Review SaaS integrations and connected accounts Map every third-party integration, API token, and delegated connection attached to approved apps before granting broader data access.

Bottom line: Shadow IT in SaaS environments is an identity governance problem because access, ownership, and offboarding often happen outside central control.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Shadow IT is now an identity governance problem first and a procurement problem second: when employees can adopt SaaS without central review, the organisation loses visibility into who can access what, where data is flowing, and which apps should be offboarded. That shifts risk from purchase oversight into lifecycle control, which is where IAM and IGA teams must reassert authority.

A few things that frame the scale:

A question worth separating out:

Q: How should IAM teams govern SaaS purchases before rollout?

A: IAM teams should treat SaaS purchasing as a control checkpoint, not a post-contract cleanup exercise. Before rollout, they should confirm federation, role design, privileged access, integration ownership, and offboarding paths. That prevents business demand from creating unmanaged access paths and makes the application governable from day one.

👉 Read our full editorial: Shadow IT from SaaS sprawl is widening identity governance gaps


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.