MI Solutions
Insights/Cutting software costs
Cutting software costs

Shadow IT: How to Find Unapproved Software and What to Do About It

What shadow IT is, why it grows, how to discover unapproved software, and a fair five-step approach to bring it under control without slowing teams down.

By the MI Solutions SAM team10 min read2 exhibits

Shadow IT is software bought or used without the knowledge of IT or procurement. A team signs up for a project tool with a credit card. A department starts a free trial that quietly becomes a paid plan. An employee connects a browser extension to company data. None of it is malicious, and much of it is useful. But it creates three problems: cost nobody manages, contracts nobody reviewed, and data nobody protects.

Why it grows

Most SaaS is now bought outside IT. Zylo's 2025 data shows lines of business control 70% of SaaS spend. When the official route takes weeks and a card payment takes minutes, people choose the card.

Shadow IT is not a discipline problem. It is a measure of how much faster the workaround is than the approved route.

The three risks

01Cost nobody manages

Duplicate tools, monthly list prices, subscriptions that outlive the project that needed them.

02Contracts nobody reviewed

Click-through terms with auto-renewal, data-processing clauses and liability limits nobody checked.

03Data nobody protects

Company data in accounts outside single sign-on, with no offboarding and no retention control.

How to find it

Discovery methodWhat it findsLimits
Expense and card dataPaid subscriptions bought by teamsFree tools; vague descriptions
Accounts payableInvoiced tools outside procurementReseller invoices hide products
Identity provider sign-insApps connected to single sign-onApps that use separate passwords
OAuth app grantsApps users connected to company accountsNeeds admin access to review
Browser or network dataWebsites and apps in usePrivacy considerations; partial coverage

Start with money. Expense and card data find the paid tools, which carry the cost and the contract risk. Then add OAuth grants, which reveal free tools connected to company email and files.

Exhibit 1
Each discovery method finds a different slice of shadow ITUnapproved apps found by method in a first discovery, illustrative 1,200-person company0255075100OAuth app grants96Expense and card data58Browser and network data44Identity providersign-ins21Accounts payable12Illustrative; apps found by several methods are counted once, under the first method that found them.Money-based methods find fewer apps but most of the cost.

A fair five-step response

Exhibit 2
Bring shadow IT into the light without slowing teams downFive steps from discovery to managed software1DISCOVERFind the toolsExpense, card, APand sign-in data2ASSESSCheck the riskData handled,security, terms,cost3DECIDEKeep, replace orretireWith the team thatuses it4CONTRACTBring it undermanagementCompany agreement,owner, renewaldate5MONITORReview monthlyNew tools fromexpense data
  1. Discover

    Paid and connected tools, from money first and identity second.

  2. Assess

    What data each one holds, its security posture, its terms and its cost.

  3. Decide

    With the team that uses it: keep, replace with an approved tool, or retire.

  4. Contract

    Put the tools you keep under a company agreement with an owner, single sign-on and a renewal date.

  5. Monitor

    Review new expense and sign-in data every month.

Make the approved route faster

Shadow IT is a symptom of friction. Publish a catalog of approved tools, pre-approve low-risk, low-cost categories, and set a service level for reviewing new requests. Our guide to SaaS approval workflows shows how to tier approvals so small purchases move fast.

Do
  • Publish a searchable catalog of approved tools by capability.
  • Pre-approve low-risk, low-cost categories.
  • Promise a review time for new requests, and keep it.
  • Treat discovered tools as signals of real needs.
Avoid
  • Blocking everything not on the list.
  • Naming and shaming teams that bought their own tools.
  • Running discovery once and never again.
  • Ignoring free tools that hold company data.

How MI One helps

Frequently asked questions

Is shadow IT always bad?

No. It often shows what people need. The goal is visibility and control, not prohibition.

Should we block unapproved apps?

Block only clear security risks. For everything else, make the approved route easier.

How often should we run discovery?

A full discovery once a year, and a monthly review of new card transactions and app grants.


Sources

See where your software budget goes

Bring your five largest vendors to a 30-minute call. Our SAM experts will show you where the savings usually hide, and how fast MI One can surface them.