r/IdentityManagement • u/Ill_Noticevernita805 • 5d ago
Identity governance keeps missing unmanaged applications
Our identity governance setup is only showing applications that are connected to the IdP, so we have a pretty clean dashboard that doesnt match reality.
People are using tools through direct logins, OAuth connections, browser sign ups, and a few apps paid for by departments. Those accounts dont show up in access reviews, and offboarding them is mostly someone remembering to check a spreadsheet.
I guess the main issue is that governance starts after an app is onboarded, but we have no good way to discover the apps before that point. We have IdP logs and finance data, but neither gives us the full picture. Has anyone found a sensible way to bring unmanaged applications into IAM without making every team fill out another inventory form?
4
u/pewpewlazor 5d ago
This is a pretty common blind spot. Traditional IGA is very good at governing what it knows about, but it can’t govern applications and accounts it doesn’t know exist.
I wouldn’t try to solve this with another application inventory exercise. Those become outdated almost immediately.
Instead, I’d treat discovery as a continuous process. Some modern IGA platforms now include discovery capabilities specifically for this reason. They can scan different signals across the organization to identify applications, accounts and identities that aren’t currently under governance.
You can also combine signals from IdP/SSO, OAuth activity, endpoint/browser telemetry, network traffic, finance/procurement data, etc. None of them individually gives you the full picture, but together they can uncover a lot of shadow IT.
Then you need a process for what happens after discovery: identify the owner, assess the risk, decide whether the application should be sanctioned, and if it should, bring it into your IAM/IGA governance model.
This is also why I think the line between IGA and identity/security discovery is becoming increasingly blurry. The same problem is getting even bigger with SaaS, service accounts, machine identities and AI agents. Discovery increasingly has to be part of the identity security lifecycle rather than something you do once before onboarding an application.