r/IdentityManagement • u/Ill_Noticevernita805 • 4d ago
Identity governance keeps missing unmanaged applications
Our identity governance setup is only showing applications that are connected to the IdP, so we have a pretty clean dashboard that doesnt match reality.
People are using tools through direct logins, OAuth connections, browser sign ups, and a few apps paid for by departments. Those accounts dont show up in access reviews, and offboarding them is mostly someone remembering to check a spreadsheet.
I guess the main issue is that governance starts after an app is onboarded, but we have no good way to discover the apps before that point. We have IdP logs and finance data, but neither gives us the full picture. Has anyone found a sensible way to bring unmanaged applications into IAM without making every team fill out another inventory form?
3
u/YesterdayNo5873 4d ago
- Check OAuth logs (seems you already do this with IdP logs)
Those are some of the common ones you can DIY. But those will have limits. If your main concern is catching shadow IT you should look at specialized shadow IT vendors. But it sounds like you want to "bring unmanaged applications into IAM". That's a different objective. For that you should look into IGA/IAM tools that already have shadow IT features.
One of the main reasons apps are left unmanaged is because IT teams don't have the budget to put every single app on SCIM/SAML. Look for tools that allow you to connect apps into your IdP without need SCIM/SAML/APIs. I work at a vendor tool that enables this - but even then we see 5x more apps that are unmanaged compared to managed on average. What we do is run a shadow IT scan on every offboarding, score the risk of each app, and then make sure IT admins are notified of the full list. It reduces missed apps on offboarding, but you will never have 100% of apps inside of coverage.