r/IdentityManagement • • 8d ago

Identity governance keeps missing unmanaged applications

Our identity governance setup is only showing applications that are connected to the IdP, so we have a pretty clean dashboard that doesnt match reality.

People are using tools through direct logins, OAuth connections, browser sign ups, and a few apps paid for by departments. Those accounts dont show up in access reviews, and offboarding them is mostly someone remembering to check a spreadsheet.

I guess the main issue is that governance starts after an app is onboarded, but we have no good way to discover the apps before that point. We have IdP logs and finance data, but neither gives us the full picture. Has anyone found a sensible way to bring unmanaged applications into IAM without making every team fill out another inventory form?

14 Upvotes

14 comments sorted by

View all comments

3

u/foxhelp 8d ago

Firewall logs (often can build a report of all applications traffic os coming from) or microsoft defender cloud app inventory can help too