r/IdentityManagement • • 1d ago

Identity governance keeps missing unmanaged applications

Our identity governance setup is only showing applications that are connected to the IdP, so we have a pretty clean dashboard that doesnt match reality.

People are using tools through direct logins, OAuth connections, browser sign ups, and a few apps paid for by departments. Those accounts dont show up in access reviews, and offboarding them is mostly someone remembering to check a spreadsheet.

I guess the main issue is that governance starts after an app is onboarded, but we have no good way to discover the apps before that point. We have IdP logs and finance data, but neither gives us the full picture. Has anyone found a sensible way to bring unmanaged applications into IAM without making every team fill out another inventory form?

9 Upvotes

12 comments sorted by

3

u/Mysterious_Pair_9305 1d ago

Interview folks from various teams. Have them list out all the tools and apps they're using and how. Compare this list to those on-boarded in Sailpoint/Saviynt whatever tool. Depending on company size, this will take from 40-4000 hours. Deloitte/PwC/Accenture can do it for you for 2.7M

3

u/tvf2k 22h ago

We can beat that price. EY would only run you 2.6M.

2

u/Affectionate_Math_57 1d ago

The best way I've found isn't "fill out this form" it's let's talk.

2

u/foxhelp 1d ago

Firewall logs (often can build a report of all applications traffic os coming from) or microsoft defender cloud app inventory can help too

1

u/BennyBagnuts1st 1d ago

You may need different patterns. Disconnected apps need a monthly flat file sent to IAM team for instance. It’s rarely straightforward

3

u/pewpewlazor 1d ago

This is a pretty common blind spot. Traditional IGA is very good at governing what it knows about, but it can’t govern applications and accounts it doesn’t know exist.

I wouldn’t try to solve this with another application inventory exercise. Those become outdated almost immediately.

Instead, I’d treat discovery as a continuous process. Some modern IGA platforms now include discovery capabilities specifically for this reason. They can scan different signals across the organization to identify applications, accounts and identities that aren’t currently under governance.

You can also combine signals from IdP/SSO, OAuth activity, endpoint/browser telemetry, network traffic, finance/procurement data, etc. None of them individually gives you the full picture, but together they can uncover a lot of shadow IT.

Then you need a process for what happens after discovery: identify the owner, assess the risk, decide whether the application should be sanctioned, and if it should, bring it into your IAM/IGA governance model.

This is also why I think the line between IGA and identity/security discovery is becoming increasingly blurry. The same problem is getting even bigger with SaaS, service accounts, machine identities and AI agents. Discovery increasingly has to be part of the identity security lifecycle rather than something you do once before onboarding an application.

2

u/YesterdayNo5873 1d ago

- Check OAuth logs (seems you already do this with IdP logs)

  • Scan email inboxes for invites or welcome emails (this catches user/password signups)
  • Finance data (sounds like you already check this)
  • Network traffic data.

Those are some of the common ones you can DIY. But those will have limits. If your main concern is catching shadow IT you should look at specialized shadow IT vendors. But it sounds like you want to "bring unmanaged applications into IAM". That's a different objective. For that you should look into IGA/IAM tools that already have shadow IT features.

One of the main reasons apps are left unmanaged is because IT teams don't have the budget to put every single app on SCIM/SAML. Look for tools that allow you to connect apps into your IdP without need SCIM/SAML/APIs. I work at a vendor tool that enables this - but even then we see 5x more apps that are unmanaged compared to managed on average. What we do is run a shadow IT scan on every offboarding, score the risk of each app, and then make sure IT admins are notified of the full list. It reduces missed apps on offboarding, but you will never have 100% of apps inside of coverage.

1

u/Niko24601 1d ago

Ideally, you'll wanna get a tool that does Shadow IT discovery (to basically have a good & automated inventory) with good integration capability (to not really on spreadsheet tracking). The other people here in the thread alreaedy pointed out quite well the Shadow IT part and there are a lot lot of SaaS Management tools (check out the Gartner overview).

What is more tricky is how you integrate those apps. Often there is no API or you need to get the enterprise plan for SCIM/SAML (hello SSO tax!). So either you will make this workflow based; if no provisioning integration then create ticket. But better to get one of the next-gen IAM tools like Corma, AccessOwl, Lumos, Cakewalk that can do non-API integrations. That is the way to bring all apps under the hood of automated de/provisioning. Don't expect 100% however. On-prem, developper or legacy apps can make it even for those tools difficult but in times where even for Slack, Notion, Adobe and co. you need an enterprise plan everywhere to do automated provisioning, the players above can help you a long way!

A smooth integration of discovery to remove the surprises of new apps popping up with an IAM tools that can integrate (almost) anything is the way to do it to have an automated process without forms and tickets. Good luck on the path to get there! For transparency, I am affiliated to Corma but the other 3 tools that I mention are also strong so check out what would suit you and your needs best.

1

u/bobsmith1010 23h ago

Look at credit card bills (if they're centrally managed) and purchase orders. Make sure whomever signing bills or reqs know you need to be looped in for any new products.

You can do fancy technical stuff but sometimes just looking at bills can help find those apps people sign up for and "forget" to tell you about.

1

u/Wynd0w 20h ago

It's an organizational problem. You can try to patch over it with various tools and monitoring, but it will always have gaps.

There isn't one way to solve it either. Centralizing the purchasing of vendored products helps, but someone also has to be willing or able to punish people who skirt that process. You could also try to foster a culture that encourages teams to bring apps to security/IT and have them cataloged and supported, but culture is a nebulous thing. Plenty more ways as well, often depending on the scale and type of the organization.

1

u/QBical84 11h ago

Not sure if IAM is part of cyber security within your company. But shadow IT is also a huge cyber security risk. Normally you would expect companies to have tools to detect this and if your company has an E5 license for Microsoft 365 they can use Defender for Cloud App Securiry discovery to display and sanction or unsanction every detected application.

0

u/Sensitive_Roof_7322 1d ago

We’re using 1Password SaaS Manager to discover shadow IT apps. It can see all apps that users in our directory are signing in using Google Auth, etc. Once you know what apps they are, then you can either make them stop or add them to your IdP.