What Are the Security Risks of Shadow IT and Unused SaaS Accounts?

What Are the Security Risks of Shadow IT and Unused SaaS Accounts?

The short answer: Shadow IT and unused SaaS accounts create security risks because you cannot protect, monitor, or properly offboard software you do not know exists. Every unknown application, forgotten login, unmanaged AI tool, and third-party connection can create another path to company data.

For businesses and MSPs, reducing that risk starts with visibility: knowing which applications are being used, which accounts are still active, what is connected to Microsoft 365 or Google Workspace, and where software is being purchased outside the normal IT process.

October is Cybersecurity Awareness Month, which makes this a good time to look beyond the security controls organizations typically focus on. Firewalls, endpoint protection, multi-factor authentication, software updates, and phishing training are all important. But they share one assumption: you already know what you are protecting.

In many organizations, that assumption no longer holds.

Employees sign up for tools with their work email. Departments purchase software on company cards without involving IT. Free trials become permanent parts of a workflow. Former employees leave behind accounts. And AI tools have introduced another rapidly growing category of applications that can interact with company data.

The stakes are significant. IBM’s 2026 Cost of a Data Breach research found that the global average cost of a data breach reached a record $4.99 million, a 12% increase from the previous year.

Visibility does not solve every cybersecurity problem. But it is difficult to secure an environment you cannot fully see.

What Is Shadow IT?

Shadow IT is software, cloud services, SaaS applications, or AI tools used inside an organization without the knowledge, approval, or oversight of the people responsible for IT or security.

It can include:

  • SaaS applications employees sign up for themselves
  • AI tools adopted without an organizational review
  • Applications connected to Microsoft 365 or Google Workspace
  • Software purchased on department or company credit cards
  • Free tools that never go through procurement
  • Applications left behind after a project ends
  • Duplicate tools being used by different departments

Shadow IT is rarely malicious.

Most employees are simply trying to solve a problem. Someone needs to edit a file, manage a project, summarize a document, automate a task, or collaborate with a customer, so they find an application that helps.

The security problem comes afterward.

The application may now contain company information or have access to company accounts, while IT may have little or no visibility into how it is being used.

Unused SaaS accounts create a related problem. These are applications and licenses that may have been approved originally but are no longer actively used. They can include accounts belonging to former employees, applications from completed projects, forgotten trials, duplicate software, and Microsoft 365 licenses that are still assigned but no longer needed.

What Are the Security Risks of Shadow IT and Unused SaaS Accounts?

The fundamental risk is straightforward: software you cannot see is difficult to secure.

Here are five ways shadow IT, dormant accounts, and unmanaged SaaS applications can increase security risk.

1. Company Data Can End Up in Applications Nobody Reviewed

When an employee uploads a customer list, contract, source code, financial information, or other company data into an unapproved application, that information is now being handled by a vendor the organization may never have reviewed.

IT and security teams may not know how the data is stored, what security controls are in place, who can access it, how long it is retained, or how the vendor would respond to a security incident.

The issue is not necessarily that the application is unsafe. The organization simply has not had an opportunity to determine whether its security practices match the company’s requirements.

2. Former Employees Can Leave Behind Access

Most employee offboarding processes cover obvious systems such as email, Microsoft 365, Google Workspace, and core business applications.

Shadow IT is harder.

An employee may have created an account for a file-sharing application, project management platform, design tool, AI assistant, or other SaaS product that never appeared on the official software list.

If IT does not know the application or account exists, it is much harder to include it in the offboarding process.

That creates a simple but important question for every organization:

When an employee leaves, do you actually know every application they were using?

3. Dormant SaaS Accounts Can Become Unmonitored Entry Points

Unused accounts are easy to forget.

They may have outdated passwords, weak authentication, old permissions, or no active owner responsible for monitoring them. Suspicious activity can also be harder to notice when nobody regularly uses the account.

That makes SaaS cleanup more than a cost-control exercise.

Removing unnecessary accounts reduces the number of identities and applications an organization needs to manage and secure.

4. Shadow AI Creates a New Visibility and Access-Control Problem

Shadow AI is the use of AI applications or models without an organization’s approval, governance, or security oversight.

It has quickly become an important extension of the traditional shadow IT problem.

An employee can paste customer information into an AI assistant, connect an AI application to files or email, or authorize a tool through an existing company identity without necessarily thinking of that decision as a cybersecurity event.

IBM’s 2026 research shows why AI security and governance have become increasingly important. More than one in five organizations studied reported a security incident involving an AI model or application, and 92% of organizations that experienced an AI-related breach lacked proper AI access controls.

For MSPs, the challenge multiplies across customers. Managing AI sprawl requires knowing which tools are being used in each client environment before you can have a meaningful conversation about governance, access, or risk.

5. Third-Party Connections Can Expand the Attack Surface

Many SaaS applications connect to Microsoft 365 or Google Workspace through OAuth, often through familiar prompts such as “Sign in with Google” or “Sign in with Microsoft.”

Depending on the permissions requested, those connections can provide ongoing access to company information or services.

Over time, an organization can accumulate dozens of third-party connections without anyone maintaining a complete picture of which applications are still needed, who uses them, or what access they have.

Every third-party application connected to a business environment should have an owner, a purpose, and an appropriate level of access.

You cannot review those connections if you do not know they exist.

Shadow IT Is Also a Software Spend Problem

The same blind spots that create security risks frequently create unnecessary spending.

Unused licenses, duplicate applications, forgotten subscriptions, and software that automatically renews without review can remain in an environment for months or years.

That means SaaS visibility connects cybersecurity and software cost optimization.

An unused Microsoft 365 license, for example, represents unnecessary spending. If it is also attached to an account that should no longer exist, it can create an unnecessary account to manage and secure.

Rather than reducing Microsoft 365 costs by removing useful functionality, businesses and MSPs can start by reconciling the licenses they pay for against the people who actually need them.

Look for:

  • Licenses assigned to former employees
  • Users with little or no recent activity
  • Duplicate or overlapping applications
  • Users on higher license tiers than their work requires
  • Software subscriptions without a clear owner
  • Applications approaching renewal that are no longer needed

BetterTracker customer SCS experienced both sides of the visibility problem. After connecting its environment, the company surfaced 102 applications it did not know about and identified 24 months of overbilling, resulting in $576,000 in savings.

How Do You Find Shadow IT and Unused SaaS Accounts?

Finding shadow IT requires looking beyond a traditional software inventory.

A complete review should consider applications connected to company identities, software being paid for, contracts that have been signed, and tools employees are actually using.

Microsoft 365 and Google Workspace are useful places to start, but neither tells the entire story on its own.

How Do I Find Apps Connected to Google Workspace?

Google Workspace administrators can review third-party applications users have authorized through their Google accounts.

In the Google Admin console, go to:

Security → Access and data control → API controls → Manage App Access

This provides visibility into applications connected through Google Workspace and helps administrators identify connections that may need further review.

But that is only one source of software discovery.

It will not necessarily reveal a SaaS application purchased on a company card, a contract owned by another department, software that does not authenticate through Google, or the other subscriptions being used across the organization.

BetterTracker’s Google Scout brings Google Workspace application visibility together with the other software signals you’re already tracking, so you can understand those applications in the context of the broader technology environment.

How Do I Find Unused Microsoft 365 Licenses?

Microsoft 365 administrators can compare assigned licenses with available usage information in the Microsoft 365 admin center to identify accounts with little or no recent activity.

A useful starting point is comparing licensing information under Billing → Licenses with activity available under Reports → Usage.

Look for:

  • Licenses assigned to former employees
  • Users with little or no recent activity
  • Unnecessary or duplicate license assignments
  • Higher-cost SKUs that may no longer match what a user needs

That works for reviewing Microsoft licensing. The bigger challenge is reconciling those findings alongside contracts, software spend, renewals, other applications, and, for MSPs, multiple customer environments.

BetterTracker’s 365 Scout brings Microsoft 365 licensing and usage insights into the same technology intelligence platform as the rest of your software data, making it easier to identify waste and determine where action is needed.

How Do I Find SaaS Subscriptions and Forgotten Software Spend?

Microsoft 365 and Google Workspace are only two parts of the software environment.

To find SaaS subscriptions that may not appear in either platform, review:

  • Company credit card transactions
  • Bank transactions
  • Expense reports
  • Vendor contracts
  • Accounts payable records
  • Departmental software purchases
  • Recurring subscription charges

Look for vendor names that do not appear in the official software inventory, recurring charges without a known owner, duplicate products, and subscriptions that continue after the associated project or employee is gone.

BetterTracker connects to financial accounts through Plaid to help surface software transactions alongside contracts, Microsoft 365, Google Workspace, and the rest of the technology environment.

For businesses trying to solve the same problem consumer subscription apps solve for individuals, you can learn more about using BetterTracker as a Rocket Money for business.

How Do I Find Shadow AI Tools?

Start with the same sources used to find traditional shadow IT.

Review applications connected to Microsoft 365 and Google Workspace, software transactions, approved software inventories, and any application telemetry available to your organization for AI tools that have not gone through the normal approval process.

Then ask three questions:

  1. What AI tools are employees using?
  2. What company data can those tools access?
  3. Who approved and owns each application?

The goal should not necessarily be to prohibit AI use. It is to understand where AI is being used so the organization can establish appropriate policies, approved tools, and access controls.

For MSPs, this becomes particularly important because the same exercise has to happen across multiple customer environments.

How Can MSPs Find Shadow IT Across Multiple Clients?

For MSPs, performing this process manually for every client quickly becomes difficult.

Each customer may have different Microsoft 365 licenses, Google Workspace connections, contracts, payment methods, SaaS applications, and AI tools.

A useful software visibility process therefore needs to answer two levels of questions:

At the client level: What software is this organization using, paying for, and connecting to its environment?

Across the MSP: Which customers have unused licenses, duplicate tools, technology gaps, upcoming renewals, or applications that need review?

That turns software visibility into something MSPs can incorporate into ongoing customer conversations rather than a one-time audit.

BetterTracker for MSPs helps MSPs bring technology intelligence together across their own business and their customer environments, so findings can become part of ongoing optimization, security, and account-growth conversations.

Bringing Software Visibility Into One View

Microsoft 365, Google Workspace, financial transactions, and contracts each tell a different part of the story.

BetterTracker brings those signals together.

Businesses can connect financial accounts through Plaid to identify software transactions, add contracts and renewal information, use 365 Scout for Microsoft 365 visibility, and use Google Scout to identify applications connected through Google Workspace.

Betty AI, BetterTracker’s AI advisor, can help teams investigate that information, ask questions about their technology environment, and identify where attention may be needed.

For MSPs, CustomerTracker extends visibility across customer environments, helping teams identify software spend, technology gaps, licensing issues, and potential optimization opportunities across clients.

The objective is not simply to create another software list.

It is to make it easier to answer questions such as:

  • What software are we actually using?
  • What appeared since our last review?
  • Which applications do we no longer need?
  • What is renewing soon?
  • Where are we paying for unused licenses?
  • What AI tools have appeared in the environment?
  • Which applications deserve a closer security review?

A Cybersecurity Awareness Month Checklist for Your SaaS Environment

Cybersecurity Awareness Month is a useful reminder to review the software attack surface that sits outside traditional security controls.

Use October to complete the following SaaS visibility audit, then turn it into a recurring process:

  1. Build a complete application inventory. Include paid software, free applications, AI tools, and applications purchased outside IT.
  2. Review Microsoft 365 and Google Workspace connections. Investigate third-party applications you do not recognize or no longer use.
  3. Review former employee access. Confirm that offboarding covered SaaS applications as well as core company systems.
  4. Remove unused licenses and dormant accounts. Reduce unnecessary spending and the number of accounts that need to be managed.
  5. Inventory AI applications. Document which AI tools employees use, what information they can access, and whether they have been reviewed.
  6. Review recurring software charges. Compare financial transactions against your approved software inventory.
  7. Assign an owner to every application. Someone should be responsible for the application’s purpose, access, contract, and renewal.
  8. Review upcoming renewals. A renewal is a natural point to reassess whether an application is still needed.
  9. Create a repeatable review schedule. Review the software environment at least quarterly and whenever employees join, leave, or change roles.

Cybersecurity Awareness Month lasts one month. Software visibility should not.

Frequently Asked Questions

What are the security risks of shadow IT?

Shadow IT can expose company data to applications that IT and security teams have not reviewed, leave former employees or unused accounts with access, and create third-party connections that are difficult to monitor. The first step in reducing shadow IT risk is identifying which applications are actually being used across the organization.

How do I find shadow IT in my company?

Start by comparing your official software inventory against company financial transactions, Microsoft 365 and Google Workspace connections, vendor contracts, and applications employees are using. Differences between those sources can reveal unapproved, forgotten, or unmanaged software.

What is shadow AI?

Shadow AI is the use of artificial intelligence tools without an organization’s approval, governance, or security oversight. Examples include employees entering company information into unapproved AI assistants or connecting AI applications to company email, files, calendars, or other systems without review.

How do I find shadow AI?

Review applications connected to Microsoft 365 and Google Workspace, software transactions, approved software inventories, and any application telemetry available to your organization. Once AI applications are identified, document who uses them, what company data they can access, and whether they have gone through the appropriate security review.

How do I find apps connected to my Google Workspace account?

Google Workspace administrators can review third-party applications under Security → Access and data control → API controls → Manage App Access in the Google Admin console. This identifies applications connected through Google Workspace. To understand those applications alongside software spend, contracts, and other technology, businesses can use BetterTracker’s Google Scout as part of a broader software inventory.

How do I find unused Microsoft 365 licenses?

Compare assigned Microsoft 365 licenses with usage information to identify former employees, inactive users, unnecessary assignments, and licenses that may no longer match a user’s needs. BetterTracker’s 365 Scout brings Microsoft 365 licensing and usage insights alongside the rest of the organization’s technology data.

How can MSPs manage AI sprawl across client environments?

MSPs need visibility into which AI applications each client uses, who is using them, what they cost, and what company resources they can access. From there, MSPs can help customers establish approved applications, access policies, ownership, and a recurring review process.

How do MSPs track software subscriptions across multiple clients?

MSPs can track software subscriptions by maintaining a per-client inventory that combines software purchases, contracts, Microsoft 365 and Google Workspace information, renewal dates, and application ownership. BetterTracker for MSPs brings those signals together across customer environments so MSPs do not have to rely on separate spreadsheets and vendor portals.

How often should a business audit its software environment?

A business should conduct a comprehensive software review at least quarterly and review application access whenever an employee joins, leaves, or changes roles. Organizations should also review applications before major renewals so unused or duplicate software can be addressed before another contract term begins.

Find the Software You Aren’t Seeing

Shadow IT, unused licenses, forgotten subscriptions, unmanaged AI applications, and third-party connections are difficult to address when the information is scattered across financial accounts, contracts, Microsoft 365, Google Workspace, and individual departments.

BetterTracker brings those signals together so businesses and MSPs can understand what is in their software environment, identify what needs attention, and make better decisions about security, spending, licensing, and renewals.

Start Your Free Trial

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top