Shadow IT is any software, hardware, cloud service or integration used inside an organization without the knowledge, approval or oversight of the IT department. It is rarely malicious. Employees adopt tools to work faster, and every unsanctioned signup quietly expands the company's attack surface.
Key facts
- Around 80% of employees admit to using applications at work that IT has not approved, according to Cisco.
- Gartner estimates that 38% of technology purchases are managed and controlled by business leaders rather than IT.
- 41% of employees have acquired, modified or created technology without their IT team's knowledge, according to IBM research.
- The fastest-growing form of shadow IT today is shadow AI: unsanctioned AI chatbots, notetakers and OAuth-connected AI assistants.
Common examples of shadow IT
| Category | Examples | Why it slips through |
|---|---|---|
| File sharing and storage | Personal Dropbox, Google Drive, WeTransfer | Faster than the sanctioned route |
| Messaging and collaboration | WhatsApp, Telegram, personal Slack workspaces | Colleagues and customers are already there |
| SaaS and productivity | Trello, Notion, Canva, free CRM tiers | A credit card or a free plan is all it takes |
| AI tools | ChatGPT and similar assistants, transcription bots | Personal accounts, no procurement step |
| Integrations and OAuth apps | "Sign in with Google" apps, calendar and mail add-ons | Granted by the user, never seen by IT |
| Devices and networks | Personal laptops and phones, home routers, hotspots | Convenience when the managed option gets in the way |
Why shadow IT happens
Employees and teams route around IT for three predictable reasons: the approved toolset lacks something they need, procurement takes too long, or they already use a tool privately and bring it to work. SaaS made this effortless. Anyone with a browser and an email address can deploy new software in minutes, and free tiers mean no expense report ever betrays the signup. Punishing employees for it treats the symptom; the cause is almost always a gap between what people need and what IT provides.
The risks of shadow IT
Invisible attack surface
Security teams cannot patch, monitor or configure what they do not know exists. Every unsanctioned account is a set of credentials, often reused and without MFA, that nobody is watching.
Data loss and data sprawl
Company data stored in personal accounts is not backed up, not covered by retention policies, and stays accessible to employees after they leave.
Persistent OAuth access
Third-party apps granted mailbox, drive or calendar scopes keep that access until someone revokes it. Abandoned grants pile up for years, and a breach at any of those vendors becomes a breach of your data. Attackers exploit the same mechanism directly through OAuth consent phishing, tricking employees into granting mailbox access to a malicious app, a technique increasingly seen alongside business email compromise.
Compliance exposure
GDPR and industry regulations follow personal data wherever employees put it. Unsanctioned tools rarely meet the processing, residency and deletion requirements the organization has committed to, and "we did not know" is not a defense auditors accept.
Compounding costs
Duplicate subscriptions, data scattered across tools with no single source of truth, and expensive migrations when a shadow tool becomes load-bearing for a whole team.
How to detect shadow IT in 30 minutes
Most shadow IT announces itself in the email and identity layer, which makes it detectable without new infrastructure:
- Audit OAuth grants (10 min). In Google Admin (Security > API controls > App access control) or Microsoft Entra (Enterprise applications), list every third-party app with granted scopes. Sort by mail, drive and calendar access. Flag anything nobody approved.
- Search inbound welcome emails (10 min). Search company inboxes for common signup phrases ("verify your email", "welcome to", "confirm your account") from the last 90 days. Every unsanctioned SaaS tool sent one on day zero.
- Scan billing signals (5 min). Search for receipt and invoice emails from SaaS vendors that finance does not recognize.
- Review your SSO and password manager logs (5 min) for apps employees access outside the sanctioned catalog.
- Repeat continuously. A one-off audit captures a snapshot. New signups happen weekly, and the OAuth grants they create persist.
Manage it, don't ban it
Organizations that ban shadow IT outright push it further underground. A better approach: publish a short acceptable-use policy that names approved tools and the data types that must never leave them, make the request path for new tools fast (days, not months), provide sanctioned alternatives for the most common shadow categories including AI, review every app before it receives OAuth scopes on company accounts, and revoke unused grants on a schedule.
How Sentaro sees shadow IT
Nearly every SaaS tool an employee adopts announces itself in email: a welcome message, a verification link, a receipt, or an OAuth consent against Google Workspace or Microsoft 365. That makes the mailbox the earliest and most complete detection point for shadow IT. Sentaro's shadow IT discovery tool uses App and Message Defense to monitor these signals continuously, surfacing new app signups, new OAuth grants and consent phishing attempts disguised as legitimate apps, so security teams see shadow IT as it appears instead of during the next annual audit.
See every app and OAuth grant touching your inbox
Sentaro deploys on Google Workspace and Microsoft 365 in minutes and surfaces every new SaaS signup, AI tool and third-party integration in your email environment.
See shadow IT discovery