Skip to main content

Shadow IT in Microsoft 365: Discovering Apps Nobody Approved

Media Shadow IT in Microsoft 365 Discovering Apps Nobody Approved

A member of staff needs to convert a PDF, transfer a large file or summarise meeting notes. The approved company tool feels inconvenient, so they find a free cloud service and sign in using their Microsoft 365 account.

The application works, the task gets completed and nobody informs IT.

That is shadow IT.

Shadow IT includes cloud applications, browser services, mobile apps and integrations being used without formal approval. Some tools are harmless and genuinely useful. Others may store company data in unknown locations, request excessive Microsoft 365 permissions or disappear entirely when the employee who introduced them leaves.

The objective is not to ban every unfamiliar application. It is to discover what employees are using, understand the risks and provide approved alternatives before sensitive data leaves your control.

What Is Shadow IT?

Shadow IT is technology used for business purposes without being reviewed, approved or managed through the organisation’s normal IT process.

Common examples include:

  • Personal file-sharing accounts
  • Free PDF conversion tools
  • AI writing and transcription services
  • Unapproved project-management platforms
  • Online design tools
  • Personal cloud storage
  • Browser extensions
  • Meeting-recording applications
  • Unauthorised Microsoft Teams apps
  • OAuth applications connected to Microsoft 365

The application may have been introduced with good intentions. Employees often adopt new tools because they are trying to solve a genuine problem quickly.

The risk comes from the organisation not knowing:

  • What data the application receives
  • Where that data is stored
  • Who can access it
  • How long it is retained
  • Whether the provider uses it for AI training
  • What happens when an employee leaves
  • Which Microsoft 365 permissions were granted
  • Whether the service meets regulatory requirements

An application does not need to contain malware to create a data-security problem.

Why Microsoft 365 Makes Shadow IT Easy

Modern cloud apps commonly offer a Sign in with Microsoft button.

That makes registration fast, but users may not realise that they are doing more than creating an account. The application may request permission to access Microsoft 365 resources such as the user’s profile, files, calendar or mailbox.

Microsoft describes consent as the process through which a user or administrator authorises an application to access a protected resource. The permissions requested are displayed during the consent process, but users may approve them without fully understanding the implications. 

Shadow IT can therefore appear in two different forms:

  1. An employee uses an external cloud service, perhaps uploading company files manually.
  2. An application becomes connected to your Microsoft 365 tenant, gaining delegated or application permissions.

Both need to be reviewed.

The Real Risks of Unapproved Apps

Sensitive Data Leaves Microsoft 365

An employee may upload:

  • Customer information
  • Contracts
  • Financial reports
  • Employee records
  • Meeting recordings
  • Source code
  • Security documentation

Once the file reaches another provider, your Microsoft 365 retention, sensitivity labels, access controls and audit processes may no longer protect it.

Applications Receive Excessive Permissions

An apparently simple calendar tool may request permission to read email. A document utility may ask for access to all files the user can open.

OAuth applications can operate quietly while retaining broad access to data on behalf of users. Microsoft Defender for Cloud Apps includes app-governance capabilities specifically because OAuth apps can hold extensive permissions and become difficult to monitor. 

Former Employees Leave Behind Connected Apps

A service may continue accessing information through an authorised application even after the original business need has ended.

Unless somebody reviews and revokes the consent, the access may remain available.

The Provider May Not Meet Your Requirements

An unapproved service may lack:

  • Suitable contractual protections
  • Appropriate data residency
  • Multi-factor authentication
  • Independent security certification
  • Reliable account deletion
  • Adequate breach-notification procedures
  • Administrative logging

Support and Continuity Become Unclear

When an employee leaves, nobody may know:

  • Which service they used
  • Which account owns the company data
  • How to export the information
  • Whether the organisation is paying for it
  • How to cancel the account

Shadow IT often becomes visible only when something stops working.

Start With Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps provides Cloud Discovery capabilities designed to identify cloud applications being used across an organisation.

Cloud Discovery can analyse traffic information and show:

  • Applications detected
  • Users and devices involved
  • Data volumes
  • Transactions
  • IP addresses
  • Application categories
  • Risk assessments

Microsoft’s Cloud App Catalog contains information on thousands of discoverable cloud applications and assigns risk scores based on security, compliance and legal factors. 

In the Microsoft Defender portal:

  1. Open Cloud Apps.
  2. Select Cloud Discovery.
  3. Open Discovered apps.
  4. Review applications by usage and risk.
  5. Filter by category, risk score, users or traffic.
  6. Investigate unfamiliar or high-volume services.

Do not focus only on applications with the lowest risk scores. A reasonably secure application may still be inappropriate if employees are uploading highly confidential information to it.

How Cloud Discovery Finds Applications

Visibility depends on supplying Defender for Cloud Apps with suitable network or endpoint data.

Common approaches include:

  • Microsoft Defender for Endpoint integration
  • Firewall log uploads
  • Proxy log collection
  • Supported secure web gateway integrations
  • Continuous Cloud Discovery

The objective is to build an ongoing view rather than analysing one historical export.

Microsoft’s Shadow IT guidance recommends reviewing discovered applications, investigating their users and traffic, assessing compliance and deciding whether each service should be sanctioned or unsanctioned. 

Licensing and available discovery features vary, so confirm what is included in your Microsoft security subscription.

Review Microsoft Entra Enterprise Applications

Cloud Discovery shows web services being used. Microsoft Entra enterprise applications reveal apps that have established a relationship with your tenant.

In the Microsoft Entra admin centre:

  1. Open Microsoft Entra ID.
  2. Select Enterprise applications.
  3. Open All applications.
  4. Review unfamiliar and recently added applications.
  5. Check owners, assignments, permissions and sign-in activity.
  6. Investigate applications without a clear business purpose.

For every application, ask:

  • Who requested it?
  • Which department uses it?
  • Is the publisher trusted?
  • Which permissions has it received?
  • Was consent granted by a user or administrator?
  • Does it still have recent activity?
  • Is there a named internal owner?
  • Is there an approved alternative?

Microsoft provides dedicated guidance for reviewing and revoking permissions granted to enterprise applications when an app is suspicious or holds more access than it requires. 

Review Application Permissions

Pay particular attention to permissions involving:

  • Reading or sending email
  • Accessing files
  • Reading calendars
  • Viewing directory data
  • Maintaining offline access
  • Managing groups or users
  • Accessing all users’ information

A legitimate application may need some of these permissions, but the business reason must be documented.

Also distinguish between:

  • Delegated permissions, where an application acts on behalf of a signed-in user
  • Application permissions, where the app can operate without an interactive user

Application permissions can be particularly powerful because the service may access data in the background.

Search the Audit Logs for Consent Activity

Microsoft Entra audit logs record application-permission activity, including permissions being granted or revoked.

Administrators can review audit logs under:

Microsoft Entra ID → Enterprise applications → Audit logs

This helps identify:

  • Recently added service principals
  • Consent granted to applications
  • Administrator consent
  • Permission changes
  • Application ownership changes

Microsoft Purview Audit can also be searched for suspicious Consent to application events during investigations. Microsoft specifically recommends using those events when looking for illicit consent grants. 

Useful questions include:

  • Which user granted consent?
  • When did it happen?
  • Which permissions were approved?
  • Was the application expected?
  • Did the consent follow a phishing message?
  • Did the application begin accessing data immediately?

Review Microsoft Teams Apps

Shadow IT does not exist only outside Microsoft 365.

Employees may add applications directly to Teams for:

  • Polling
  • Project management
  • File storage
  • Automation
  • Meetings
  • AI assistance
  • Customer support

Review the Teams admin centre to determine:

  • Which apps are available
  • Which apps have been installed
  • Which users are using them
  • Whether custom apps are permitted
  • Which permission and setup policies apply

Avoid allowing every third-party Teams app simply because it appears inside Microsoft’s marketplace.

Each application should still have a business purpose, owner and security review.

Classify Each Discovered Application

A simple classification model helps turn a long application list into practical decisions.

Sanctioned

The application is approved and supported.

It should have:

  • A business owner
  • Security and privacy review
  • Appropriate contract
  • Controlled user access
  • Documented data handling
  • Joiner and leaver procedures

Tolerated

The application is not a preferred company standard, but its risk is currently acceptable for limited use.

Define:

  • Permitted data
  • Approved users
  • Review date
  • Conditions for continued use

Under Review

The application’s purpose or risk is unclear.

Consider temporarily limiting usage while gathering information.

Unsanctioned

The application presents unacceptable risk or duplicates an approved service.

Reasons may include:

  • Excessive permissions
  • Unsafe data handling
  • No valid owner
  • Serious compliance gaps
  • Known security concerns
  • No business need

Defender for Cloud Apps lets organisations tag applications as sanctioned or unsanctioned. Unsanctioned applications can then be monitored or blocked through supported endpoint and network controls. 

Do Not Block First and Ask Questions Later

Immediately blocking every unknown application may interrupt important work and drive usage onto personal devices that you cannot monitor.

Before blocking, determine:

  • Who uses the app
  • What task it supports
  • What data it handles
  • Whether there is an approved replacement
  • How users will migrate their data
  • Whether an exception is genuinely required

Then communicate:

  • Why the service is being restricted
  • When access will stop
  • Which approved tool should be used
  • How to request a review or exception
  • How existing company data should be removed

Good shadow IT management fixes the underlying business problem rather than merely closing a website.

Restrict User Consent

Allowing employees to consent to any application increases the chance that unreviewed services gain Microsoft 365 access.

Microsoft Entra consent policies can restrict user consent according to factors such as publisher verification and permission risk.

A practical approach may allow users to approve only low-impact permissions from verified publishers, while applications requesting broader access require administrative review.

Microsoft also provides an admin consent workflow so users can request approval rather than being forced to abandon the tool or find an uncontrolled workaround. 

A useful approval process should check:

  • Business justification
  • Publisher identity
  • Requested permissions
  • Data processed
  • Contract and privacy terms
  • Security certifications
  • Application owner
  • Exit and deletion process

Block Unsanctioned Apps Where Necessary

When Microsoft Defender for Cloud Apps is integrated with Defender for Endpoint, apps marked as unsanctioned can be blocked on managed endpoint devices.

Microsoft notes that unsanctioned app domains may take time to propagate to endpoints, so blocking should be tested rather than assumed to be immediate. 

Other blocking options may include:

  • Secure web gateways
  • Firewalls
  • DNS filtering
  • Browser controls
  • Microsoft Entra Internet Access
  • Conditional Access for connected applications

Blocking works best on managed devices. Employees using personal phones or unmanaged computers may still be able to reach the service unless access and data-protection controls cover those routes too.

Give Employees an Approved App Catalogue

People are less likely to create shadow IT when they can easily find an approved tool.

Publish a simple catalogue showing:

Business need

Approved application

Large file transfer

Approved secure-sharing service

PDF editing

Approved PDF platform

Project management

Company project tool

Meeting transcription

Approved Microsoft 365 service

AI assistance

Approved Copilot or AI platform

External collaboration

Managed SharePoint or Teams workspace

Include:

  • What the tool is for
  • How to request access
  • What information may be used with it
  • Where to get support
  • Which alternatives are prohibited

A six-week approval process for a simple productivity tool practically guarantees shadow IT.

Create a Lightweight Approval Route

Not every application needs a three-month supplier assessment.

Use a risk-based process.

Low-risk apps may need:

  • Basic publisher verification
  • Limited permissions
  • No confidential data
  • Named owner
  • Short security review

High-risk apps may need:

  • Full security assessment
  • Data-protection review
  • Contractual terms
  • Penetration or certification evidence
  • Administrator consent
  • Restricted pilot
  • Formal senior approval

The process should be proportionate enough that users actually follow it.

Monitor Continuously

Shadow IT is not a one-time cleanup project.

New services appear constantly, and existing applications can change ownership, terms or permissions.

Defender for Cloud Apps supports discovery policies that can alert when applications matching defined risk conditions are detected. 

A useful review cycle is:

Monthly

Review:

  • Newly discovered apps
  • New enterprise applications
  • User and admin consent
  • High-risk applications
  • Apps with sudden traffic increases

Quarterly

Review:

  • Sanctioned and unsanctioned lists
  • Application owners
  • OAuth permissions
  • Inactive apps
  • Approved-app catalogue
  • Exceptions

Annually

Review:

  • Application governance policy
  • Consent configuration
  • Discovery coverage
  • Supplier contracts
  • Data-processing arrangements
  • Employee awareness

Shadow IT Audit Checklist

  • Enable continuous cloud discovery.
  • Review the highest-volume applications.
  • Investigate low-risk-score and high-data-use services.
  • Export your enterprise application inventory.
  • Review OAuth and Microsoft Graph permissions.
  • Search consent and service-principal audit events.
  • Review Microsoft Teams applications.
  • Assign an owner to every approved app.
  • Tag applications as sanctioned or unsanctioned.
  • Provide approved alternatives before blocking.
  • Restrict user consent.
  • Enable an admin consent workflow.
  • Repeat the review regularly.

Common Shadow IT Mistakes

Assuming Unknown Means Malicious

The app may be solving a genuine business need that approved systems do not address.

Looking Only at Browser Traffic

Connected OAuth and enterprise applications may retain access even when their websites are rarely visited.

Reviewing Applications but Ignoring Data

A low-risk service can still be inappropriate for payroll or customer records.

Blocking Without an Alternative

Employees move the workflow to personal accounts or devices.

Approving an App Forever

Application ownership, permissions and supplier risk can change.

Allowing Consent Without Governance

A convincing sign-in screen can lead employees to grant access they do not understand.

Final Thoughts

Shadow IT exists because employees want to work efficiently.

The answer is not to treat every unfamiliar application as misconduct. It is to make usage visible, evaluate the real risk and offer secure tools that meet the same need.

Use Microsoft Defender for Cloud Apps to discover web services in use. Review Microsoft Entra enterprise applications and permissions. Search consent audit events. Examine Teams apps and assign a clear owner to every approved service.

Then classify each application:

  • Approve it
  • Restrict it
  • Replace it
  • Block it

Most importantly, keep the approval process practical.

When secure tools are easy to find and new services can be reviewed promptly, employees have far less reason to build an invisible technology estate of their own.

Unsure Which Cloud Apps Your Employees Are Using?

Hamilton Group can help you discover and control shadow IT across Microsoft 365.

Our experts can help you:

  • Configure Microsoft Defender for Cloud Apps
  • Enable continuous Cloud Discovery
  • Identify risky and unapproved services
  • Audit Microsoft Entra enterprise applications
  • Review OAuth permissions and consent
  • Configure user-consent restrictions
  • Introduce an admin consent workflow
  • Approve or block cloud applications
  • Build an approved application catalogue
  • Establish an ongoing application-governance process

Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts to uncover the cloud applications your organisation is already using.