Shadow IT is a symptom. Treating it as misconduct guarantees more of it.
Staff adopt tools because the sanctioned route was too slow, not because they wanted to create risk. Discovery matters because company data ends up in services nobody assessed, and a leaver keeps access to tools IT never knew existed. The fix is mostly about making the official path faster.

- Start with financeCard data beats security tooling
- Sanction, do not confiscateMost tools are fine
- OAuth appsStanding access nobody audits
- AI toolsThe newest and least governed
Eight sources, and the first one is not a security tool.
Finance data, which is the single best source
Expense claims and corporate card statements show what people actually pay for, with a name and an amount attached. Nothing else gives you that. A twelve-month export, sorted by merchant, surfaces the subscriptions nobody declared, and it takes an afternoon. Most organisations never try this because shadow IT is filed as a security problem and the best evidence sits in finance.
Consented applications in your Microsoft tenant
Third-party applications that users have granted access to company data. Microsoft describes OAuth apps as often behaving unnoticed while holding extensive permissions to access data in other apps on behalf of an employee, which is exactly why they matter. Each is standing access that survives password changes and is invisible unless somebody goes looking.
Sign-in and identity logs
Where people are authenticating with their work identity tells you which services they use, including ones the organisation never bought. This is particularly useful for spotting services where staff signed up with a work email and a personal password, which is the most common shadow IT pattern and the one with the worst offboarding consequences.
Network and DNS data where it exists
Firewall, proxy or DNS logs show what is being reached from your network. Microsoft Defender for Cloud Apps performs shadow IT discovery from an assessment of network traffic against an app catalogue, and describes it as showing which apps are really being used both on and off the corporate network. Coverage is the limitation: an employee on their own connection is not in these logs.
Mail, which nobody thinks to search
Signup confirmations, invoices, trial expiry notices and password resets from SaaS providers all land in mailboxes. Searching for those patterns across the tenant is a legitimate administrative action and it reliably surfaces services that appear in no other source, including free tools that never touched a card and never appeared in finance data.
AI tools, the newest and least governed category
Staff pasting company material into consumer AI services is a genuinely new shadow IT category and it moves faster than policy. The mechanism is what matters: content leaving your control into a service you have no agreement with, no data handling terms from, and no ability to retrieve from. Worth discovering deliberately rather than assuming your existing controls cover it, because most were designed before this existed.
Risk ranking, so the response is proportionate
Once discovered, each service needs a decision rather than a reflex. Defender for Cloud Apps assesses discovered apps against more than 90 risk indicators and assigns risk rankings, which is useful input. The judgement that matters is yours: what data reaches it, how many people use it, whether a supported alternative exists, and what breaks if you remove it.
The offboarding problem, which is the real exposure
A departing employee loses access to everything IT knows about. Everything IT does not know about, they keep, often indefinitely, frequently including the customer data or documents they put there. This is the concrete harm from shadow IT for most UAE businesses, ahead of any theoretical breach, and discovery is the only thing that closes it.
People hide tools from an IT function that confiscates them.
How you run this determines what you find. An investigation into misconduct produces concealment and one round of discoveries. An amnesty produces a list you can actually work with, and it keeps producing one.
- Nobody adopted an unsanctioned tool to create risk. They adopted it because they had a job to do and the official route was slow, or unavailable, or they asked once and nothing happened. That is a service delivery finding about IT before it is a compliance finding about them, and treating it the other way round is why these exercises so often produce a single sweep and then nothing.
- Run it as an amnesty. Say plainly that the objective is to bring things into the open and support them where possible, that nobody is in trouble for declaring a tool, and that the alternative outcome is company data sitting somewhere nobody can retrieve it from. In our experience declarations under those terms surface things no automated discovery would have found.
- Most of what you find is fine and should simply be sanctioned. A well-run team using a good project tool has solved a problem, and the correct response is to procure it properly, get terms in place and add it to onboarding. Removing it because it arrived through the wrong door is how IT acquires a reputation that guarantees the next tool is hidden better.
- Reserve blocking for the genuinely indefensible: services holding regulated data with no agreement, tools with a poor security position, and anything where the data cannot be recovered. Then fix the cause. If three teams independently adopted the same category of tool, that is a gap in what you provide, and closing it is worth more than any control you could apply.
Four things that make this produce a lasting result.
We start where the evidence actually is
Finance data first, then tenant and identity data, then network sources, then tooling if it is still warranted. That order is deliberate: the cheapest sources reveal the most, and it is common to reach a good enough picture without buying anything. A programme that opens with a procurement decision has the sequence backwards.
We run it as an amnesty and say so up front
We help you write the message to staff before any discovery begins. It says what is happening, why, that nobody is in trouble for declaring a tool, and what the organisation will do with what it learns. This single step changes the quality of the result more than any technical method, because it converts people from subjects of an investigation into participants.
We recommend sanctioning far more than blocking
Most of what we find should be procured properly rather than removed. The default recommendation is to bring it in with terms, an owner and an offboarding step. Blocking is reserved for services where regulated data has no agreement behind it or where the data cannot be recovered, and we will tell you when we think a proposed block is an overreaction.
We fix the cause, or it recurs within a year
If getting a small tool approved takes three weeks, shadow IT is the rational response and it will return. The lasting output of this work is usually a fast, published route for small requests and a repeatable check on new consented applications, not the list of what was found. Without those, you will run the same exercise again in eighteen months.
Six situations where undiscovered services become a real problem.
An organisation with data protection obligations
Under UAE federal data protection law, and under the DIFC and ADGM regimes for entities in those free zones, personal data processed on your behalf remains your responsibility regardless of who signed up for the service. A tool holding customer records that nobody assessed, with no agreement and no retention position, is an obligation you carry without knowing it.
A business answering client security questionnaires
Questions about where client data is stored and which subprocessors touch it are routine now, and they have to be answered accurately by somebody who signs. If departments have adopted tools independently, the honest answer is not known, and discovering that during a questionnaire is considerably worse than discovering it beforehand.
A company with meaningful staff turnover
Every departure is a test of whether offboarding covers services IT knows about only. Sales tools, design platforms, file sharing and note applications routinely retain access for former employees, along with whatever they put there. This is the most concrete harm from shadow IT and the easiest to demonstrate to a board.
A regulated or healthcare organisation
Where a sector framework requires you to know your information assets and control third-party access, undiscovered services are a direct gap. For healthcare entities under ADHICS in Abu Dhabi, asset management and third party security are separate control domains, and a clinical team using an unapproved tool sits awkwardly inside both.
A financial firm under supervisory expectations
Outsourcing and third-party arrangements attract supervisory attention, and an arrangement nobody recorded is still an arrangement. For DIFC, ADGM and Central Bank supervised firms the difficulty is not usually the tool itself but the inability to demonstrate that anybody assessed it, which is a governance answer rather than a technical one.
Any business where staff have started using AI tools
The newest category and the one moving fastest. What matters is the mechanism rather than alarm: company material leaving your control into a service you have no agreement with and cannot retrieve from. Most existing acceptable use policies predate this entirely, so the useful output is specific guidance about what may and may not be pasted, plus a sanctioned option that is good enough that people use it.
What actually happens after shadow IT is discovered.
| Feature | Discover and sanction | Discover and confiscate | Never look |
|---|---|---|---|
Complete-enough picture of what is used | One sweep only | ||
Staff declare tools voluntarily afterwards | Not applicable | ||
Useful tools brought under proper terms | Removed | ||
Genuinely risky services dealt with | Sometimes | ||
Company data recoverable from the services used | Partly | ||
Leavers lose access to everything | |||
Root cause in service delivery addressed | |||
Usage after the exercise | Visible | Hidden better | Unknown |
Relationship between IT and the business | Improved | Damaged | Unchanged |
Position if a regulator or client asks | Defensible | Partial | None |
Discovery methods, honestly compared.
| Source | What it misses | |
|---|---|---|
| Expense claims and card statements | Free tools, and anything paid personally without a claim | |
| Consented applications in the tenant | Services never connected to your Microsoft identity | |
| Sign-in and identity logs | Services where staff used a personal account entirely | |
| Firewall, proxy or DNS logs | Anything used off the corporate network, so most remote work | |
| Mailbox search for signup and invoice patterns | Tools registered to a personal email address | |
| Asking people directly, under an amnesty | Whatever they forget, or still do not trust you with | |
| A CASB such as Defender for Cloud Apps | Depends on the traffic it can see and connectors configured | |
| Browser or endpoint telemetry | Personal devices, which is where the riskiest usage often is | |
| All of the above combined | Still not everything. Aim for the material, not the complete |
Five stages, and the announcement comes before the discovery.
- 1
Agree the framing and tell people
A short message from leadership rather than from IT, setting out that the objective is to bring tools into the open and support them where possible, that declaring something carries no consequence, and why it matters that company data is retrievable. We help write it. Doing discovery first and explaining afterwards produces a worse result and a lasting cost in trust.
- 2
Run the free sources
Twelve months of expense and card data sorted by merchant, consented applications in the tenant, identity sign-in data, and a mailbox search for signup, trial and invoice patterns. Alongside those, structured conversations with department heads. This stage alone usually produces the great majority of the picture at no tooling cost.
- 3
Add network and tooling sources only if needed
Firewall, proxy or DNS data if you have it, and a CASB such as Microsoft Defender for Cloud Apps where the gap justifies it. We are explicit that network sources are blind to anyone working off your network, which in a hybrid organisation is a large share of the usage, so we do not present them as complete.
- 4
Decide service by service, with the business
Sanction, replace, or remove, with the reasoning recorded. What data reaches it, how many people depend on it, whether a supported alternative exists and what breaks if it goes. Most items should end up sanctioned with proper terms and an owner, and where we recommend removal we set out what the affected team needs instead.
- 5
Close the cause and make it repeatable
A fast published route for small tool requests, offboarding extended to cover services outside the core estate, and a periodic check on new consented applications. Without these the list you just built is a snapshot, and the same exercise will be needed again within about a year.
What organisations ask about shadow IT.
Fifteen checks, and five of them cost nothing.
Free discovery, this week
- Export twelve months of card and expense data, sorted by merchantThe single highest-yield hour in this whole exercise.
- List third-party applications with consent in your tenantStanding access that survives password changes.
- Search mailboxes for signup, trial and invoice patternsFinds free tools that never appear in finance data.
- Ask each department head what their team actually usesUnder an amnesty. You will be told more than you expect.
- Check what your firewall or DNS logs already showFree if you have them, though blind to remote work.
Deciding what to do
- Does any of it hold personal or regulated data?That is your obligation regardless of who signed up.
- Which are used by a team rather than an individual?Team adoption means it solved a real problem.
- Does a supported alternative already exist?If yes, the gap was communication rather than capability.
- Could you retrieve your data if you stopped using it tomorrow?Often not, and this is the argument for acting now.
- Is anything holding data with no agreement in place at all?The clearest case for immediate action.
Stopping it recurring
- How long does it take to get a new tool approved?If the answer is weeks, you have your root cause.
- Is there a fast, published route for a small request?Not the same process as a major platform purchase.
- Does offboarding cover services outside the core estate?The concrete harm, and usually unaddressed.
- Is anyone monitoring new consented applications?They appear continuously and silently.
- Do staff know what they may and may not put into AI tools?Specific guidance, not a general prohibition nobody follows.
The pages around this one.
Microsoft 365 security audit
The tenant side, including consented applications and guest accounts, which is one of the discovery sources this exercise uses.
Third party risk audit
The suppliers you did choose, assessed from who can actually reach your systems rather than from a questionnaire.
UAE PDPL compliance
The federal data protection obligations that apply to personal data wherever it sits, including in services nobody assessed.
Export twelve months of card data and sort it by merchant.
One hour, no tooling, no budget, and it is the single most revealing step in this whole exercise. If what comes back is uncomfortable, the rest of the work is mostly about making your sanctioned path fast enough that people stop needing to go around it.
Related Services
Explore more solutions that work great with this service
Microsoft 365 Security Audit
Tenant review, and how far back your evidence really goes
Third Party Risk Audit
Who can actually reach your systems, and what to do about it
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
Virtual CISO Dubai
Security governance and accountability, not more tools
DLP Solutions
Microsoft Purview DLP and labels
Microsoft Entra
Identity and access management solutions
NIST CSF 2.0 Assessment
Know where you stand, without committing to certification