Skip to content
Under attack?Get emergency help now
All articles
14 September 2026F1 IT Solutions

Shadow IT: The Apps Your Staff Connected to Your Data

Shadow ITMicrosoft 365CloudIdentity SecurityCybersecurityManaged IT

Shadow IT used to mean someone installing software they were not supposed to. IT could see it on the machine, remove it, and the problem was solved. That version of the problem has largely gone away. What replaced it is harder to see and considerably harder to undo.

Today a member of staff finds a tool that looks useful, a meeting note taker, a PDF converter, a scheduling assistant, an AI writing helper. They sign up with their work email, a prompt appears asking for permission to access their mail, files or calendar, and they click Accept. Nothing is installed. No admin approval is needed. The tool now holds standing access to company data through an API, and it will keep that access until somebody explicitly takes it away.

Why the consent screen is the real problem

Most businesses worry about shadow IT in terms of spend and duplication. Two teams paying for two project tools, licences nobody is tracking. That is a real cost, but it is not the security issue.

The security issue is that a single click can hand an unknown third party read access to a mailbox or a document library. Once granted, that permission behaves very differently to a password:

  • It does not expire. The connection persists whether or not the person keeps using the tool, and often whether or not they still work for you.
  • Multi-factor authentication does not stop it. The user already authenticated. The app is now acting with permissions they gave it, not stealing a login.
  • A password reset does not revoke it. Changing the user's password leaves the grant in place.
  • It survives offboarding. Disabling an account closes the front door, but an app connected to that account may still hold a token. This is the same gap we look at in employee offboarding and the access your leavers still have.

Attackers understand this. Consent phishing, where a convincing looking app requests permissions rather than credentials, is now a standard technique precisely because it sidesteps the controls most businesses have invested in.

What Microsoft has already tightened

Microsoft has moved the default position in the right direction. Under the Microsoft managed consent policy, ordinary users can no longer consent on their own to the highest impact permissions, including broad access to files, SharePoint sites and mailboxes. Those requests now need an administrator.

That is a meaningful improvement, and it is worth checking your tenant is actually on that setting rather than a legacy one inherited from an older configuration. It is not the whole answer though. Plenty of useful permissions still sit below that line, older grants made before the policy changed are untouched, and none of it covers tools that never connect to Microsoft 365 at all. Someone pasting client data into a free web service is invisible to your tenant settings entirely.

Finding what is already connected

You cannot govern what you have not looked at. A first pass is usually quick and almost always surprising.

  • Review enterprise applications in Microsoft Entra. Look at what is registered, what permissions each app holds, who consented and when. Anything unrecognised, unused or from an unverified publisher is a candidate for removal.
  • Check for stale grants. Apps tied to accounts that have since been disabled are the clearest wins. Remove them.
  • Look at expenses and card statements. Software bought on a personal or departmental card is the classic route by which a tool enters the business without IT ever seeing it.
  • Ask, rather than hunt. A short, non punitive survey asking which tools people actually rely on tends to surface more than a technical scan, because it catches the services that never touched your tenant.

If you already have conditional access and reporting in place as part of a wider Microsoft 365 and cloud management setup, most of this data is sitting there waiting to be read.

Bringing it under control without blocking the business

The instinct after that first review is usually to shut everything down. That rarely holds. People adopted these tools because something in their day was slow, and removing the tool without addressing the reason simply pushes the behaviour further out of sight.

A workable approach has three parts.

Set a default of admin approval for anything that touches data. Combine that with an admin consent workflow so the request arrives in a queue rather than hitting a dead end. The user gets a clear route, and you get a record.

Make approval quick. If a sensible request takes two weeks, staff will route around you. A same week answer for low risk tools buys a great deal of goodwill and keeps requests coming through the front door.

Review on a schedule. Treat connected apps the way you treat any other supplier with access to your systems. A quarterly look at what is still connected, what is still needed and what should be revoked keeps the list from drifting. It is the same discipline as managing third-party vendor risk, applied to software rather than firms.

Alongside that, people need to know what the permission prompt actually means. Most staff read it as a formality, not as a decision to share the mailbox. A short, specific piece of security awareness training on that single screen changes behaviour more reliably than a policy document nobody opens.

A takeaway

Shadow IT is not really a discipline problem. It is a sign that people are trying to work faster than the tools you gave them allow. The risk is not that they experiment, it is that nobody knows what they connected, and that those connections quietly outlive the reason they were made.

Start with the list. Once you can see what is connected to your data, the decisions about what to keep get much easier.

Want this handled for you?

Talk to the F1 team about cybersecurity, AI and managed IT for your business.