We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Shadow IT discovery
Shadow IT discovery, UAE

Shadow IT is a symptom. Treating it as misconduct guarantees more of it.

Staff adopt tools because the sanctioned route was too slow, not because they wanted to create risk. Discovery matters because company data ends up in services nobody assessed, and a leaver keeps access to tools IT never knew existed. The fix is mostly about making the official path faster.

Book a shadow IT discoverySee how we find it
Shadow IT discovery and SaaS governance for UAE organisations
  • Start with financeCard data beats security tooling
  • Sanction, do not confiscateMost tools are fine
  • OAuth appsStanding access nobody audits
  • AI toolsThe newest and least governed
How we find it

Eight sources, and the first one is not a security tool.

Most shadow IT programmes start by buying discovery tooling. That is the third thing to do, not the first. The sources below are ordered by how much they reveal per unit of effort, and the top two cost nothing and are available to every organisation today.

Finance data, which is the single best source

Expense claims and corporate card statements show what people actually pay for, with a name and an amount attached. Nothing else gives you that. A twelve-month export, sorted by merchant, surfaces the subscriptions nobody declared, and it takes an afternoon. Most organisations never try this because shadow IT is filed as a security problem and the best evidence sits in finance.

Consented applications in your Microsoft tenant

Third-party applications that users have granted access to company data. Microsoft describes OAuth apps as often behaving unnoticed while holding extensive permissions to access data in other apps on behalf of an employee, which is exactly why they matter. Each is standing access that survives password changes and is invisible unless somebody goes looking.

Sign-in and identity logs

Where people are authenticating with their work identity tells you which services they use, including ones the organisation never bought. This is particularly useful for spotting services where staff signed up with a work email and a personal password, which is the most common shadow IT pattern and the one with the worst offboarding consequences.

Network and DNS data where it exists

Firewall, proxy or DNS logs show what is being reached from your network. Microsoft Defender for Cloud Apps performs shadow IT discovery from an assessment of network traffic against an app catalogue, and describes it as showing which apps are really being used both on and off the corporate network. Coverage is the limitation: an employee on their own connection is not in these logs.

Mail, which nobody thinks to search

Signup confirmations, invoices, trial expiry notices and password resets from SaaS providers all land in mailboxes. Searching for those patterns across the tenant is a legitimate administrative action and it reliably surfaces services that appear in no other source, including free tools that never touched a card and never appeared in finance data.

AI tools, the newest and least governed category

Staff pasting company material into consumer AI services is a genuinely new shadow IT category and it moves faster than policy. The mechanism is what matters: content leaving your control into a service you have no agreement with, no data handling terms from, and no ability to retrieve from. Worth discovering deliberately rather than assuming your existing controls cover it, because most were designed before this existed.

Risk ranking, so the response is proportionate

Once discovered, each service needs a decision rather than a reflex. Defender for Cloud Apps assesses discovered apps against more than 90 risk indicators and assigns risk rankings, which is useful input. The judgement that matters is yours: what data reaches it, how many people use it, whether a supported alternative exists, and what breaks if you remove it.

The offboarding problem, which is the real exposure

A departing employee loses access to everything IT knows about. Everything IT does not know about, they keep, often indefinitely, frequently including the customer data or documents they put there. This is the concrete harm from shadow IT for most UAE businesses, ahead of any theoretical breach, and discovery is the only thing that closes it.

The framing that decides whether this works

People hide tools from an IT function that confiscates them.

How you run this determines what you find. An investigation into misconduct produces concealment and one round of discoveries. An amnesty produces a list you can actually work with, and it keeps producing one.

  • Nobody adopted an unsanctioned tool to create risk. They adopted it because they had a job to do and the official route was slow, or unavailable, or they asked once and nothing happened. That is a service delivery finding about IT before it is a compliance finding about them, and treating it the other way round is why these exercises so often produce a single sweep and then nothing.
  • Run it as an amnesty. Say plainly that the objective is to bring things into the open and support them where possible, that nobody is in trouble for declaring a tool, and that the alternative outcome is company data sitting somewhere nobody can retrieve it from. In our experience declarations under those terms surface things no automated discovery would have found.
  • Most of what you find is fine and should simply be sanctioned. A well-run team using a good project tool has solved a problem, and the correct response is to procure it properly, get terms in place and add it to onboarding. Removing it because it arrived through the wrong door is how IT acquires a reputation that guarantees the next tool is hidden better.
  • Reserve blocking for the genuinely indefensible: services holding regulated data with no agreement, tools with a poor security position, and anything where the data cannot be recovered. Then fix the cause. If three teams independently adopted the same category of tool, that is a gap in what you provide, and closing it is worth more than any control you could apply.
Ask us to run it as an amnesty rather than an investigation
How we run it

Four things that make this produce a lasting result.

A discovery exercise that finds everything and changes nothing is a common outcome. Most of the difference is in how it is introduced and what happens to the findings.

We start where the evidence actually is

Finance data first, then tenant and identity data, then network sources, then tooling if it is still warranted. That order is deliberate: the cheapest sources reveal the most, and it is common to reach a good enough picture without buying anything. A programme that opens with a procurement decision has the sequence backwards.

We run it as an amnesty and say so up front

We help you write the message to staff before any discovery begins. It says what is happening, why, that nobody is in trouble for declaring a tool, and what the organisation will do with what it learns. This single step changes the quality of the result more than any technical method, because it converts people from subjects of an investigation into participants.

We recommend sanctioning far more than blocking

Most of what we find should be procured properly rather than removed. The default recommendation is to bring it in with terms, an owner and an offboarding step. Blocking is reserved for services where regulated data has no agreement behind it or where the data cannot be recovered, and we will tell you when we think a proposed block is an overreaction.

We fix the cause, or it recurs within a year

If getting a small tool approved takes three weeks, shadow IT is the rational response and it will return. The lasting output of this work is usually a fast, published route for small requests and a repeatable check on new consented applications, not the list of what was found. Without those, you will run the same exercise again in eighteen months.

When this matters most

Six situations where undiscovered services become a real problem.

Shadow IT is tolerable right up to the moment somebody asks a question you cannot answer. These are the moments that question tends to arrive.

An organisation with data protection obligations

Under UAE federal data protection law, and under the DIFC and ADGM regimes for entities in those free zones, personal data processed on your behalf remains your responsibility regardless of who signed up for the service. A tool holding customer records that nobody assessed, with no agreement and no retention position, is an obligation you carry without knowing it.

A business answering client security questionnaires

Questions about where client data is stored and which subprocessors touch it are routine now, and they have to be answered accurately by somebody who signs. If departments have adopted tools independently, the honest answer is not known, and discovering that during a questionnaire is considerably worse than discovering it beforehand.

A company with meaningful staff turnover

Every departure is a test of whether offboarding covers services IT knows about only. Sales tools, design platforms, file sharing and note applications routinely retain access for former employees, along with whatever they put there. This is the most concrete harm from shadow IT and the easiest to demonstrate to a board.

A regulated or healthcare organisation

Where a sector framework requires you to know your information assets and control third-party access, undiscovered services are a direct gap. For healthcare entities under ADHICS in Abu Dhabi, asset management and third party security are separate control domains, and a clinical team using an unapproved tool sits awkwardly inside both.

A financial firm under supervisory expectations

Outsourcing and third-party arrangements attract supervisory attention, and an arrangement nobody recorded is still an arrangement. For DIFC, ADGM and Central Bank supervised firms the difficulty is not usually the tool itself but the inability to demonstrate that anybody assessed it, which is a governance answer rather than a technical one.

Any business where staff have started using AI tools

The newest category and the one moving fastest. What matters is the mechanism rather than alarm: company material leaving your control into a service you have no agreement with and cannot retrieve from. Most existing acceptable use policies predate this entirely, so the useful output is specific guidance about what may and may not be pasted, plus a sanctioned option that is good enough that people use it.

Three responses

What actually happens after shadow IT is discovered.

The middle column is the common one and it is the worst outcome available, because it produces the appearance of control while pushing usage somewhere you can no longer see it at all.
Complete-enough picture of what is used
Discover and sanction
Discover and confiscateOne sweep only
Never look
Staff declare tools voluntarily afterwards
Discover and sanction
Discover and confiscate
Never lookNot applicable
Useful tools brought under proper terms
Discover and sanction
Discover and confiscateRemoved
Never look
Genuinely risky services dealt with
Discover and sanction
Discover and confiscateSometimes
Never look
Company data recoverable from the services used
Discover and sanction
Discover and confiscatePartly
Never look
Leavers lose access to everything
Discover and sanction
Discover and confiscate
Never look
Root cause in service delivery addressed
Discover and sanction
Discover and confiscate
Never look
Usage after the exercise
Discover and sanctionVisible
Discover and confiscateHidden better
Never lookUnknown
Relationship between IT and the business
Discover and sanctionImproved
Discover and confiscateDamaged
Never lookUnchanged
Position if a regulator or client asks
Discover and sanctionDefensible
Discover and confiscatePartial
Never lookNone
Feature
Discover and sanction
Discover and confiscate
Never look
Complete-enough picture of what is used
One sweep only
Staff declare tools voluntarily afterwards
Not applicable
Useful tools brought under proper terms
Removed
Genuinely risky services dealt with
Sometimes
Company data recoverable from the services used
Partly
Leavers lose access to everything
Root cause in service delivery addressed
Usage after the exercise
VisibleHidden betterUnknown
Relationship between IT and the business
ImprovedDamagedUnchanged
Position if a regulator or client asks
DefensiblePartialNone
What each source reveals

Discovery methods, honestly compared.

No single source is complete, which is why the exercise combines several. The right-hand column is what each one misses, because that is the part vendors do not mention and it is what determines the order we work in.
SourceWhat it misses
Expense claims and card statementsFree tools, and anything paid personally without a claim
Consented applications in the tenantServices never connected to your Microsoft identity
Sign-in and identity logsServices where staff used a personal account entirely
Firewall, proxy or DNS logsAnything used off the corporate network, so most remote work
Mailbox search for signup and invoice patternsTools registered to a personal email address
Asking people directly, under an amnestyWhatever they forget, or still do not trust you with
A CASB such as Defender for Cloud AppsDepends on the traffic it can see and connectors configured
Browser or endpoint telemetryPersonal devices, which is where the riskiest usage often is
All of the above combinedStill not everything. Aim for the material, not the complete
How the exercise runs

Five stages, and the announcement comes before the discovery.

Typically two to three weeks. The order matters: telling people what is happening before you start is what makes the declarations useful, and declarations consistently find things no automated method does.
  1. 1

    Agree the framing and tell people

    A short message from leadership rather than from IT, setting out that the objective is to bring tools into the open and support them where possible, that declaring something carries no consequence, and why it matters that company data is retrievable. We help write it. Doing discovery first and explaining afterwards produces a worse result and a lasting cost in trust.

  2. 2

    Run the free sources

    Twelve months of expense and card data sorted by merchant, consented applications in the tenant, identity sign-in data, and a mailbox search for signup, trial and invoice patterns. Alongside those, structured conversations with department heads. This stage alone usually produces the great majority of the picture at no tooling cost.

  3. 3

    Add network and tooling sources only if needed

    Firewall, proxy or DNS data if you have it, and a CASB such as Microsoft Defender for Cloud Apps where the gap justifies it. We are explicit that network sources are blind to anyone working off your network, which in a hybrid organisation is a large share of the usage, so we do not present them as complete.

  4. 4

    Decide service by service, with the business

    Sanction, replace, or remove, with the reasoning recorded. What data reaches it, how many people depend on it, whether a supported alternative exists and what breaks if it goes. Most items should end up sanctioned with proper terms and an owner, and where we recommend removal we set out what the affected team needs instead.

  5. 5

    Close the cause and make it repeatable

    A fast published route for small tool requests, offboarding extended to cover services outside the core estate, and a periodic check on new consented applications. Without these the list you just built is a snapshot, and the same exercise will be needed again within about a year.

Straight answers

What organisations ask about shadow IT.

Export twelve months of corporate card and expense data and sort it by merchant. It is the highest-yield hour available in this entire exercise, it costs nothing, and most organisations never do it because shadow IT gets filed as a security problem while the best evidence sits in finance. It will not find free tools or anything paid personally without a claim, which is why the exercise combines sources, but it is the right place to start.

Usually not, and the instinct to do so is what makes these programmes fail. Most of what you find is a team solving a real problem with a reasonable tool, and the correct response is to procure it properly, get terms in place, assign an owner and add it to onboarding and offboarding. Blocking should be reserved for services holding regulated data with no agreement behind them, or where you could not retrieve your data. Removing something useful because it arrived through the wrong door guarantees the next tool is hidden more carefully.

Almost never in the sense that matters. People adopt unsanctioned tools because they had work to do and the official route was slow, unavailable, or they asked once and nothing happened. That is a finding about IT service delivery before it is a finding about them. Framing it as misconduct produces concealment, and the practical result is that you get one round of discoveries and then a workforce that has learned to be more careful about what it tells you.

Third-party applications a user has granted permission to access company data through your Microsoft identity. Microsoft describes OAuth apps as often behaving unnoticed while holding extensive permissions to access data in other apps on behalf of an employee, which is precisely the problem. They are standing access that survives a password change, they accumulate silently, and unless somebody reviews them periodically nobody will notice a new one. This is one of the highest-value free checks available.

Possibly, and not as the first step. Microsoft Defender for Cloud Apps performs shadow IT discovery from an assessment of network traffic against an app catalogue, assigns risk rankings and assesses apps against more than 90 risk indicators, which is genuinely useful. Whether you need it depends on what the free sources leave uncovered and whether you want ongoing monitoring rather than a point-in-time picture. We would rather establish the gap first than open with a purchase, and we cannot tell you which licence tiers include it because we have not verified that.

It is the newest shadow IT category and it moves faster than policy, so it is worth addressing specifically rather than assuming existing controls cover it. The mechanism is what matters: company material leaving your control into a service you have no agreement with and cannot retrieve from. Most acceptable use policies predate this entirely. The response that works is specific guidance about what may and may not be pasted, combined with a sanctioned option good enough that people actually use it, because a blanket prohibition against a genuinely useful tool will simply be ignored.

Directly. Under UAE federal data protection law, and under the DIFC and ADGM regimes for entities in those free zones, personal data processed on your behalf remains your responsibility regardless of who signed up for the service. A tool holding customer records with no agreement, no data handling terms and no retention position is an obligation you are carrying without knowing it. Discovery is the only way to establish the position, which is why this work usually pays for itself in the data protection programme rather than in the security one.

Offboarding, ahead of anything more dramatic. A departing employee loses access to everything IT knows about and keeps access to everything it does not, frequently including the customer data, documents or designs they put there. That is concrete, demonstrable and happens with every departure, whereas a breach of an unsanctioned service is possible but hypothetical. If you need to make the case internally, run the offboarding argument rather than the breach argument.

No, and anybody promising otherwise is overselling. Every source has a blind spot: finance data misses free tools, network logs miss anyone working off your network, identity logs miss services used with a personal account entirely, and asking people misses whatever they forget or still do not trust you with. Combining sources gets you a good picture of what is material, which is the realistic and sufficient objective. Aim for the material rather than the complete.

Two to three weeks for a typical UAE organisation. The free sources take a few days. The department conversations take longer because they depend on people being available, and they are worth waiting for because declarations consistently surface things no automated method finds. Deciding what to do with each service is the part that needs the business rather than IT, and that pace is set by how quickly your organisation makes decisions.

It happens, most often customer or personal data in a service with no agreement behind it, or a former employee who still has access to something holding company material. We raise those immediately rather than saving them for the report, and the first action is usually to secure the data and establish who has had access rather than to remove the service, since removal can destroy the evidence and sometimes the data. Whether anything further follows, including a notification obligation, is a decision for you with your advisers.

Make the sanctioned path faster than the unsanctioned one, which is the only intervention that works durably. In practice that means a published route for small tool requests that is genuinely quick and separate from the process for major platform purchases, someone empowered to say yes to modest things, and a clear answer when the request is declined. Add periodic review of new consented applications and extend offboarding to cover services outside the core estate. Controls without the speed fix produce a repeat of this exercise in about a year.

The discovery is IT work. The framing should come from leadership, because a message from IT saying nobody is in trouble is less persuasive than the same message from the chief executive or chief operating officer. The decisions about which services to sanction belong to the business, since they involve trade-offs about how teams work. Where this is run entirely inside IT it tends to produce a technically complete list and very little change.

It overlaps on consented applications and guest accounts, and it is otherwise a different exercise. A tenant audit examines the configuration of a platform you own. This examines services nobody chose centrally, most of which sit entirely outside your tenant and will never appear in it. Organisations frequently want both, and running them together is efficient because the tenant data is one of the discovery sources, but neither substitutes for the other.

We scope per organisation, driven mostly by headcount, how many departments are involved and whether you want ongoing monitoring afterwards. What we will tell you free in the first conversation is exactly how to run the finance data export yourself, because it is the single most revealing step and you should not pay anybody to do it. If that export tells you everything you need, the rest of the engagement may not be necessary and we will say so.
Find it yourself first

Fifteen checks, and five of them cost nothing.

The first group you can run this week without tooling or budget. The second is what to do with what you find. The third is fixing the cause, which is the only part that stops it recurring.

Free discovery, this week

  • Export twelve months of card and expense data, sorted by merchant
    The single highest-yield hour in this whole exercise.
  • List third-party applications with consent in your tenant
    Standing access that survives password changes.
  • Search mailboxes for signup, trial and invoice patterns
    Finds free tools that never appear in finance data.
  • Ask each department head what their team actually uses
    Under an amnesty. You will be told more than you expect.
  • Check what your firewall or DNS logs already show
    Free if you have them, though blind to remote work.

Deciding what to do

  • Does any of it hold personal or regulated data?
    That is your obligation regardless of who signed up.
  • Which are used by a team rather than an individual?
    Team adoption means it solved a real problem.
  • Does a supported alternative already exist?
    If yes, the gap was communication rather than capability.
  • Could you retrieve your data if you stopped using it tomorrow?
    Often not, and this is the argument for acting now.
  • Is anything holding data with no agreement in place at all?
    The clearest case for immediate action.

Stopping it recurring

  • How long does it take to get a new tool approved?
    If the answer is weeks, you have your root cause.
  • Is there a fast, published route for a small request?
    Not the same process as a major platform purchase.
  • Does offboarding cover services outside the core estate?
    The concrete harm, and usually unaddressed.
  • Is anyone monitoring new consented applications?
    They appear continuously and silently.
  • Do staff know what they may and may not put into AI tools?
    Specific guidance, not a general prohibition nobody follows.
Related reading

The pages around this one.

Microsoft 365 security audit

The tenant side, including consented applications and guest accounts, which is one of the discovery sources this exercise uses.

Learn more

Third party risk audit

The suppliers you did choose, assessed from who can actually reach your systems rather than from a questionnaire.

Learn more

UAE PDPL compliance

The federal data protection obligations that apply to personal data wherever it sits, including in services nobody assessed.

Learn more
Next step

Export twelve months of card data and sort it by merchant.

One hour, no tooling, no budget, and it is the single most revealing step in this whole exercise. If what comes back is uncomfortable, the rest of the work is mostly about making your sanctioned path fast enough that people stop needing to go around it.

Book a shadow IT discoveryCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Microsoft 365 Security Audit

Tenant review, and how far back your evidence really goes

Learn more

Third Party Risk Audit

Who can actually reach your systems, and what to do about it

Learn more

UAE PDPL Compliance

Federal Decree-Law 45 of 2021 readiness and operations

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

Virtual CISO Dubai

Security governance and accountability, not more tools

Learn more

DLP Solutions

Microsoft Purview DLP and labels

Learn more

Microsoft Entra

Identity and access management solutions

Learn more

NIST CSF 2.0 Assessment

Know where you stand, without committing to certification

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy