Shadow IT in a Small Business: How to Find and Manage It
How to find the unapproved apps your staff already use, with menu paths for Microsoft 365 and Google Workspace, and a light approval process.
Shadow IT is any app, cloud service, or device that staff use for work without the business having approved it: a personal Dropbox, a free AI chatbot, a project board someone signed up for with a work email. To manage it, first find it (ask staff, check expense reports, and review the connected-apps lists in Microsoft 365 or Google Workspace), then sort each tool into approve, replace, or block, and give people a quick way to request new tools.
What Is Shadow IT, and Why Does It Happen?
It is rarely misbehavior. Someone needed to send a large file, convert a PDF, or summarize a long document, and found a tool that did it in two minutes. Signing up for most cloud apps requires nothing more than an email address.
The issue is not that these tools are bad. It is that nobody at the business has looked at them, so nobody knows what data is in them or who can reach it.
What Are the Actual Risks?
- Data you cannot get back. Files in a personal cloud account stay with the person when they leave. The business cannot revoke access or recover the content.
- Accounts nobody knows to close. An app signed up for with a work email is not on any offboarding list. See our guide to onboarding and offboarding.
- Broad permissions granted with one click. “Sign in with Microsoft” or “Sign in with Google” can give an outside app ongoing access to a person’s mailbox, calendar, or files.
- Regulated data in the wrong place. For a practice covered by HIPAA, a vendor that handles patient information generally needs a business associate agreement first. A free consumer tool will not have one. Similar issues arise for firms under the FTC Safeguards Rule. This is general information, not legal advice.
- No backup. Data that lives only in someone’s personal account is not part of your business backups.
How Do You Find Unsanctioned Apps?
Use several methods. Each one catches things the others miss. For an office of 10 to 25 people, plan on roughly half a day for a first pass through all of them.
1. Ask your staff
Frame it as “help us support what you actually use,” not as an audit. Ask each person which sites and apps they use in a normal week, including AI tools and anything on their phone. Make it clear nobody is in trouble. This is the fastest method and the only one that reliably surfaces tools used from personal devices.
2. Review expense reports and card statements
Search company card statements, reimbursement claims, and your accounting software for software subscriptions. Look for recurring small charges and for vendors you do not recognize. Anything paid personally and expensed is, by definition, a tool the business never evaluated. Also search shared mailboxes for “welcome,” “verify your email,” and “your trial” messages.
3. Microsoft 365: check which apps have access
In the Microsoft Entra admin center, go to Entra ID > Enterprise apps > All applications. This lists the third-party apps that people in your organization have signed in to or granted permissions to with their work accounts. Open an app to see its permissions and which users have used it.
Then look at how consent is configured. Under Enterprise apps > Consent and permissions > User consent settings, Microsoft’s documentation notes that by default all users can consent to apps for permissions that do not require an administrator, which can include access to their own mailbox. Microsoft recommends the option “Allow user consent for apps from verified publishers, for selected permissions.” You can also choose “Do not allow user consent.”
If you restrict consent, turn on the admin consent workflow under Consent and permissions > Admin consent settings. Staff who hit a blocked app can then send a request to a named reviewer, who gets an email. Without it, people simply see an error and look for another workaround.
4. Microsoft Defender for Cloud Apps
The consent list only shows apps connected to work accounts. To see cloud services people merely visit, you need traffic data. Microsoft Defender for Cloud Apps analyzes traffic logs against a catalog of more than 31,000 cloud apps and scores each one on more than 90 risk factors.
Licensing matters here:
| What you have | What you get |
|---|---|
| Microsoft 365 Business Premium (includes Entra ID P1) | Cloud App Discovery, a subset of Defender for Cloud Apps. Microsoft lists it as included with Entra ID P1. It works from firewall or proxy logs that you upload manually or automatically. |
| Business Premium plus the Microsoft Defender Suite add-on | Full Defender for Cloud Apps, including native integration with Defender for Endpoint (so discovery works from the computers themselves, in or out of the office), OAuth app permission review with the ability to revoke access, and anomaly detection. Listed at $10 per user per month, paid yearly, as of September 2026. |
For many small offices, methods 1 through 3 plus the included discovery feature are enough. The add-on makes more sense for firms with regulated data or a largely remote staff.
5. Google Workspace: app access control
In the Google Admin console, go to Security > Access and data control > API controls, then Manage App Access. Google’s app access control documentation describes the list of third-party apps that have been granted access to your users’ Google data, and lets you mark each app as Trusted, Limited, Specific Google data, or Blocked.
On the same page, you can restrict which Google services (such as Drive and Gmail) third-party apps may reach, and decide what happens with apps you have not reviewed. Google also lets users request access to an unconfigured app, which puts the request in the Admin console for review.
6. Network and DNS logs
A firewall or a DNS filtering service can report which cloud services are being reached from the office network. This catches tools on shared computers and devices that are not enrolled anywhere. It will not see activity from home networks unless the filtering runs on the laptop itself.
What to Do With What You Find
Put everything into one list: the app, who uses it, what it is for, what data goes into it, and how people sign in. Then sort:
| Decision | When it applies | Next step |
|---|---|---|
| Approve | It fills a real need, the vendor is reputable, and it holds no sensitive data or has suitable terms | Move it to a business-owned account, turn on MFA or single sign-on, add it to the approved list and the offboarding checklist |
| Replace | You already pay for something that does the job, for example OneDrive or SharePoint in place of a personal file-sharing account | Show people how to do the same task in the approved tool, move the data, then close the old account |
| Block | It handles sensitive data with unsuitable terms, or duplicates an approved tool with no benefit | Explain why, offer the alternative, then block it in consent settings or DNS filtering |
Check the “replace” column carefully before paying for anything new. Microsoft 365 and Google Workspace already include file sharing, forms, chat, video meetings, and scheduling. Our posts on OneDrive for Business and SharePoint cover the file-sharing side.
A Light Approval Process That People Will Use
If asking takes longer than signing up, people will skip asking. Keep it to one page.
- Publish the approved list. Group it by task: file sharing, messaging, e-signature, AI assistants, password storage. Put it where staff will see it.
- One way to ask. A short form or a dedicated mailbox, with five questions: What is the tool? What will you use it for? What information will go into it? Does it have a cost? Who else needs it?
- A named decision maker and a time limit. For example, an answer within two business days. A “no” should come with an alternative.
- Five checks before approving. Who is the vendor? What data will it hold? Does it support MFA or sign-in through Microsoft or Google? What do the terms say about how your data is used, including for AI training? How do you export data and close accounts?
- Business ownership. Approved tools are registered to a business email, with credentials in the company password manager and at least two administrators.
- A review every six months. Repeat the discovery steps, remove tools nobody uses, and update the list.
A note on AI tools
Requests for AI assistants deserve their own line in the process. The same five checks apply, with extra attention to the data terms: consumer and business plans from the same provider can differ on whether your inputs are used to train models and how long they are kept. Decide which assistant the business supports, say plainly which kinds of information must never be pasted into any other one, and put both on the approved list. If you use Microsoft 365, our guide to Microsoft 365 Copilot for small business covers the built-in option.
When a Light Touch Is Enough
A five-person office with no regulated data does not need discovery software or a formal policy. A conversation, a short approved list, MFA on the main accounts, and tighter app consent settings cover most of the risk. Put more structure in place if you hold patient, financial, or legal records, if staff work mostly from personal devices (see our BYOD policy guide), or if a cyber insurance or customer questionnaire asks how you control software.
Common Mistakes
- Blocking first and asking later. People route around blocks. Offer the approved alternative at the same moment.
- Treating it as a discipline issue. Reports dry up, and the tools move to personal phones where nothing can see them.
- Approving a tool but leaving it on a personal account. The risk is the ownership, not the app.
- Doing discovery once. New tools appear constantly. A scheduled review keeps the list honest.
- Forgetting mobile apps and browser extensions. They request the same permissions as any other connected app.
Common Questions
Is shadow IT always bad?
No. It is useful information about where your approved tools fall short. Many unsanctioned apps are reasonable products that simply need a business-owned account and MFA. The problem is lack of visibility and ownership. A good outcome from discovery is often a better approved toolkit, not only a list of blocked apps.
How can you see which apps have access to your Microsoft 365 data?
Sign in to the Microsoft Entra admin center as an administrator and open Entra ID, then Enterprise apps, then All applications. Each entry shows the permissions granted and the users who have signed in. Review any app with access to mail or files, and remove the ones nobody recognizes or needs.
Is Microsoft Defender for Cloud Apps needed to manage shadow IT?
Not necessarily. Staff conversations, expense reviews, and the connected-apps lists in Microsoft 365 or Google Workspace cost nothing and find most of it. Business Premium also includes a reduced Cloud App Discovery feature. The full product is worth considering when you need discovery from laptops outside the office or the ability to review and revoke app permissions centrally.
Should we block ChatGPT and other AI tools?
A blanket block tends to push use onto personal devices. A more workable approach is to choose one assistant on a business plan with suitable data terms, approve it, state clearly what information must not go into any other tool, and restrict the rest through consent settings or DNS filtering if needed.
How often should we review the apps in use?
Every six months suits most small offices, plus a check whenever someone leaves. Add a quick review of the connected-apps list in Microsoft 365 or Google Workspace each quarter, since that takes only a few minutes and catches new permissions soon after they are granted.
How Coastal Growth Co. Can Help
We can run the discovery pass for you: reviewing the connected apps and consent settings in Microsoft 365 or Google Workspace, checking network logs, and turning the results into an approve, replace, or block list with a one-page request process. Our cloud, email, and AI services cover moving people onto the tools you already pay for and setting up an approved AI assistant, and ongoing reviews can be part of managed IT support. Scope and price are agreed first. Reach us through the contact page.
- shadow IT
- SaaS security
- Microsoft 365
- Google Workspace
- small business
Need a hand with this?
I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.
Let's talk arrow_forward