Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What happens when organisations try to secure unmanaged…
Governance, Ownership & Risk

What happens when organisations try to secure unmanaged apps without improving user experience?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Governance, Ownership & Risk

They usually end up with inconsistent adoption and more shadow IT. If the secure option is slower or harder than the workaround, workers will choose the workaround. Over time, that creates blind spots in access control, more manual support work, and a wider attack surface. Security only scales when the approved path is also the practical path.

Why Security Breaks Down When the Approved Path Is Frictional

The core problem is adoption, not policy. If users can reach their goal faster through an unmanaged app, they will route around the control, even when the managed option is technically safer. That creates a gap between intended policy and actual behaviour, which is where shadow IT grows.

In practice, friction changes the security model in two ways. First, it reduces visibility because teams no longer see all the apps, data paths, and access relationships in use. Second, it weakens control enforcement because the official workflow is no longer the default workflow, so controls only protect a shrinking share of activity.

What the Organisation Starts Losing Over Time

Once the workaround becomes the practical norm, the organisation accumulates unmanaged accounts, duplicate workflows, and inconsistent access decisions. That usually means more manual support work, more exceptions, and less reliable auditability. The issue is not just convenience, it is that the security boundary stops matching how work actually gets done.

Shadow IT also makes standardisation harder. Different teams choose different tools, different permissions, and different sharing patterns, which increases the chance that sensitive data or privileged actions sit outside the centrally managed control set. The result is a wider attack surface, even if no single app looks especially risky on its own.

Why User Experience Becomes a Security Control

For unmanaged apps, security controls that ignore usability usually lose to user pressure. A secure option that is slower, harder to access, or requires too many steps will often be bypassed in favour of a less controlled alternative. That is why the practical path has to be the approved path if the control is meant to scale.

Good security design therefore treats user experience as part of control effectiveness, not as a separate concern. The point is not to remove every obstacle, but to make the secure workflow easy enough that users do not need to choose between productivity and compliance.

Risk and Threat Considerations

When unmanaged apps proliferate, the main risk is loss of control over where data, credentials, and business actions flow. That can create blind spots in access control, logging, and incident response, while also increasing the chance that attackers find a less governed entry point or a weaker sharing pattern.

Failure mechanism: Users bypass frictionful controls, shift work into unsanctioned tools, and create parallel access paths that security teams cannot consistently inventory, monitor, or revoke.

Impact: The organisation gets weaker detection, more manual remediation, greater exposure of sensitive data, and a larger attack surface that can persist even after the original control gap is noticed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-6 — Access Control ManagementUnmanaged apps create inconsistent access paths and weak revocation coverage.
Recommendation — Standardise access paths and revoke unsanctioned accounts or permissions promptly.
NIST CSF 2.0ID.AM-02 — Software Platforms and Applications Are InventoriedShadow IT grows when applications and their use are not inventoried.
PR.AA-01 — Identities and Credentials Are Issued, Managed, Verified, Revoked, and AuditedWorkarounds often create unmanaged accounts and inconsistent credential governance.
GV.OC-02 — Internal and External Stakeholders Are Identified and Their Requirements Are Understood and DocumentedSecurity fails when user needs are not aligned with the approved workflow.
Recommendation — Inventory approved applications and close visibility gaps created by unmanaged tools. Govern identities and credentials for every sanctioned workflow and remove orphaned access. Document user workflow requirements so controls fit how work is actually performed.
OWASP ASVSV13 — ConfigurationFrictionless, predictable configuration supports secure adoption of the approved path.
Recommendation — Reduce configuration friction so the secure option is practical for ordinary users.

Practitioner Guidance

What to prioritise: Measure whether the secure workflow is actually the shortest credible path to task completion. If adoption is poor, treat that as a control failure, not a training issue.

What to verify: Check whether the managed path preserves speed for the most common user journeys, especially onboarding, sharing, approvals, and recurring access. If those steps are slow, users will build alternatives around them.

Practitioner takeaway: Security that users avoid is not a durable control, it is a temporary policy. The control only works when the sanctioned path is easier to use than the workaround.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org