Join our Newsletter — 33% off our NHI Course

Shadow IT and SaaS access gaps: what IAM teams need now

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: 52% of employees have downloaded applications without IT approval and 34% of company apps are not protected by SSO, according to 1Password’s Access-Trust Gap research, highlighting how SaaS governance breaks down when discovery and lifecycle controls lag usage. The real issue is not just shadow IT, but unmanaged access across sanctioned and unsanctioned apps alike.

Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “70% of IT and security pros say SSO is falling short – Here’s how to close the gap”.

Key questions

Q: What breaks when SaaS apps are used outside SSO and central IAM?

A: The main failure is lifecycle control.

Q: Why do shadow IT apps create renewal and compliance risk?

A: Shadow IT bypasses approved inventory and review processes, which means the organisation may renew an app it cannot fully account for.

Q: How can organisations tell whether SaaS access governance is actually working?

A: They should look for three signals: low numbers of orphaned accounts, consistent entitlement recertification, and rapid revocation when users change roles or leave.

Practitioner guidance

  • Map SaaS inventory beyond SSO coverage Build a living inventory that includes federated apps, direct sign-ups, web-based tools, and locally hosted software used for work.
  • Review OAuth grants as access paths Inventory third-party OAuth consents separately from user accounts and federation settings.
  • Extend offboarding to non-SSO apps Make employee exit and role-change workflows trigger revocation across every connected application, not only the identity provider.

Bottom line: SaaS governance fails when identity teams can only manage the apps that have already been federated, because the rest of the estate stays outside review and revocation.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

SSO has become a boundary assumption, not a governance strategy: The article shows that many organisations still equate federated login with control, even though a large share of SaaS activity happens outside that boundary. That assumption fails because discovery, approval, and offboarding do not end at authentication. The practitioner conclusion is that SaaS governance has to be measured by lifecycle coverage, not by SSO penetration alone.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: What should IAM teams prioritise when SaaS access is fragmented?

A: IAM teams should prioritise continuous discovery first, because discovery determines what can be governed. After that, they should focus on offboarding coverage, OAuth consent review, and the apps that cannot be federated so the programme reflects actual usage rather than the limited view inside SSO.

👉 Read our full editorial: SaaS access governance is failing beyond SSO coverage


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.