Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Shadow IT and shadow SaaS: what identity teams need to change


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15754
Topic starter  

TL;DR: Shadow IT persists because employees adopt SaaS faster than approval and visibility processes can keep up, and Grip Security’s guidance argues for identity-first discovery, risk-tiering, and coordinated controls across SSO, MFA, and token revocation. The real shift is that shadow IT has become a governance problem for IAM, IGA, and SaaS security teams, not just a usage-policy issue.

NHIMG editorial — based on content published by Grip Security: How to Detect and Manage Shadow IT in Cybersecurity

By the numbers:

  • 83% of respondents admitted that they chose an alternate app for some use cases even though the feature was available in their primary sanctioned platform.
  • Lior Yaari said it is not uncommon for Grip to uncover 8-10x more SaaS accounts than enterprises were aware of.

Questions worth separating out

Q: How should security teams identify shadow data across cloud and SaaS environments?

A: Start with data discovery across sanctioned and unsanctioned repositories, then map each sensitive copy to the identities that can access it.

Q: Why does shadow IT create an IAM problem instead of only a procurement problem?

A: Shadow IT becomes an IAM problem because every unsanctioned application creates its own identities, permissions, and lifecycle obligations.

Q: What do organisations get wrong about shadow IT?

A: They often treat shadow IT as a procurement issue when it is usually a visibility and lifecycle failure.

Practitioner guidance

What's in the full article

Grip Security’s full article covers the operational detail this post intentionally leaves for the source:

  • The five-step detection and control framework with specific workflow actions for each stage.
  • Examples of how to correlate SaaS account discovery to users, groups, and business units.
  • Guidance on enforcing SSO, MFA, token revocation, and stop-use actions across relevant systems.
  • The article’s discussion of shadow AI, including browser extensions, copilots, and automated action loops.

👉 Read Grip Security’s full guide to detecting and managing shadow IT →

Shadow IT and shadow SaaS: what identity teams need to change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15339
 

Identity-first governance is the only workable model for shadow SaaS. Shadow IT is no longer just a procurement problem or a policy exception. Once an account is created with corporate identity, the security issue becomes lifecycle control over an unmanaged non-human access path, which sits squarely in NHI and IAM governance. Programmes that still depend on app inventories alone will keep missing the actual control point.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: Who should own shadow SaaS remediation when an app is already in use?

A: Ownership should sit with the identity, security, and business stakeholders together because the issue spans access, data use, and operational need. Security can enforce controls, but the business must justify the tool and confirm whether the app should be sanctioned, constrained, or removed.

👉 Read our full editorial: Shadow IT governance depends on identity-first discovery and control



   
ReplyQuote
Share: