banner-image
left hexagon image right hexagon image

How to Uncover Unsanctioned Cloud Apps Before They Become a Security Risk

If you want to uncover unsanctioned cloud applications in your organisation, don’t start with a policy document. 

Start with your browser history. 

The cloud environment most businesses actually use rarely matches the one shown on the IT architecture diagram. Instead, it evolves through dozens of small shortcuts: 

  • A quick file-sharing tool used “just this once”
  • A free online app that solved a problem faster than internal systems
  • A browser plug-in installed to meet a deadline
  • An AI feature quietly activated inside a tool you already subscribe to 

In the moment, none of these actions feel risky. They feel efficient and productive. 

But over time, they create a fragmented environment where business data is spread across tools that were never formally approved. Access becomes difficult to manage, offboarding becomes inconsistent, and sharing permissions rarely match the level of risk involved. 

For many organisations, this is where shadow IT begins to create real exposure. 

If you’re unsure how visible your cloud usage actually is, our Cyber Security Consultancy services can help organisations identify hidden risks and implement practical governance controls. 

 

Why Unsanctioned Cloud Apps Are a Bigger Issue in 2026 

Shadow IT has existed for years, but the scale and speed of adoption have changed significantly. 

Research referenced in Microsoft’s Shadow IT guidance suggests most IT teams believe employees are using around 30–40 cloud applications, when in reality the average organisation may interact with over 1,000 different apps across its environment. 

Even more concerning, Microsoft reports that around 80% of employees use non-sanctioned apps that have not been reviewed against company policy. 

This gap between perceived usage and actual usage is where many risks emerge. 

Now add a new factor: AI capabilities embedded within existing tools. 

According to the Cloud Security Alliance, artificial intelligence is increasingly built directly into everyday software platforms rather than existing as separate tools. 

This means organisations can introduce AI-related risk without anyone intentionally signing up for a new AI product. 

Research referenced by the organisation also highlights that: 

  • 54% of employees say they would use AI tools even without company approval
  • An IBM security report found 20% of organisations experienced breaches linked to unauthorised AI use, adding an average of $670,000 (£530,000+) to breach costs 

External sources: 

  • Microsoft Shadow IT guidance
  • IBM security research reports 

The takeaway is clear: shadow IT is no longer just a governance issue. It is a measurable cyber risk. 

And in 2026, simply blocking applications is rarely an effective solution. 

Cloud tools are now deeply embedded into how people work. If organisations remove access without providing a secure alternative, employees often find another workaround. 

 

Why Blocking Apps First Usually Makes Things Worse 

It is tempting to treat unsanctioned tools as a disciplinary problem. 

But starting with bans often pushes the issue further underground. 

Two common outcomes usually follow: 

  1. Employees become better at hiding the tools they are using
  2. They simply switch to another tool that may be equally risky 

In either case, the organisation has not reduced the risk. It has only reduced visibility. 

A more effective approach is to begin with visibility and context. 

Rather than focusing purely on the application itself, organisations should evaluate how the tool is being used and whether it introduces meaningful exposure. 

Some apps may prove perfectly acceptable. Others may need restrictions or additional controls. A smaller number may require removal entirely. 

The key is making those decisions based on evidence rather than assumptions. 

For organisations looking to build this kind of visibility, Sedcom often helps clients implement monitoring and governance frameworks through our Managed IT Services and Cyber Security services. 

 

A Practical Workflow to Identify Unsanctioned Cloud Apps 

Managing cloud sprawl is not a one-off project. It should become a repeatable process that runs periodically or continuously. 

A simple workflow can make this manageable. 

1. Discover What Is Actually Being Used

Start by building a real inventory of applications in use. 

Many organisations already collect the signals required to do this, including: 

  • Endpoint telemetry
  • Identity and login logs
  • Network or DNS traffic
  • Browser activity 

Microsoft’s guidance emphasises that a dedicated discovery phase is essential because organisations cannot manage tools they have not first identified. 

 

 2. Analyse How Applications Are Being Used

Simply knowing an application exists is not enough. 

Look at how people interact with it. 

Important questions include: 

  • Who is accessing the application?
  • Are administrative actions being performed?
  • Is data being shared externally or with personal accounts?
  • Are former employees still connected to the system? 

These behaviours often reveal more risk than the tool itself. 

 

 3. Score and Prioritise Risk

Not every unsanctioned application represents the same level of danger. 

A simple risk assessment should consider: 

  • The sensitivity of the data involved
  • How information is being shared
  • Whether strong identity controls are in place
  • The level of administrative visibility available
  • Whether embedded AI features could process sensitive data 

This allows organisations to prioritise their response rather than trying to fix everything at once. 

 

4. Classify and Tag Applications

Clear categorisation helps organisations manage cloud usage over time. 

Applications can be labelled as: 

  • Sanctioned
  • Restricted
  • Unsanctioned 

Microsoft recommends tagging applications in this way because it allows teams to filter activity, monitor trends and enforce consistent policies. 

 

5. Take Appropriate Action

Once applications are categorised, organisations can apply the right response. 

Possible actions include: 

  • Issuing guidance or warnings to users
  • Restricting certain sharing or permissions
  • Implementing monitoring controls
  • Blocking applications that pose unacceptable risk 

Importantly, changes should be communicated clearly to avoid disruption and help employees understand why the changes are being made. 

 

The New Operating Model: Discover, Decide, Enforce 

Unsanctioned cloud apps are unlikely to disappear anytime soon. 

If anything, they will continue to grow as AI capabilities become embedded into more everyday software platforms. 

The goal is not to block everything. 

Instead, organisations should aim to build a repeatable model: 

Discover what is in use > Decide what is acceptable > Enforce those decisions consistently. 

When this approach becomes part of everyday IT operations, cloud application sprawl stops being a surprise and becomes a controlled part of the environment. 

 

Need Help Gaining Visibility Over Your Cloud Environment? 

If your organisation is unsure how many cloud applications are actually in use, you are not alone. 

Sedcom helps UK organisations: 

  • Identify shadow IT and unsanctioned applications
  • Improve Microsoft 365 and cloud governance
  • Reduce risk introduced by AI-enabled tools
  • Implement practical cyber security controls 

Explore our Cyber Security Services or contact us to discuss how we can help you gain visibility and control without slowing productivity.

Related News & Blogs

The “Zombie” SaaS Audit: Finding the 3 Apps Your Former Employees Still Access 

Most businesses are quick to disable a departing employee’s email account. The laptop gets returned, passwords are reset, and the…
Read More

Why Human Behaviour Is Still Your Biggest Cybersecurity Risk 

Cybersecurity conversations often focus on sophisticated attacks, advanced malware, and complex technical vulnerabilities. In reality, many breaches begin with something far more…
Read More

Clean Desk 2.0: Why Your Home Office Is Now a Security Risk

In the traditional office, a “clean desk” policy was simple. Lock away sensitive documents, clear down paperwork, and never leave…
Read More