Every organisation has systems outside its own inventory: a marketing microsite, a data science VM, a SaaS trial that became load-bearing, a demo environment with production data.
Why it happens
Rarely malice. Usually the official route was slow, so somebody used a corporate card and solved their problem. Treat that as a signal about your own processes, because a programme that punishes shadow IT simply makes it better hidden.
How to find it
- Expenditure. Card statements and invoices find SaaS faster than any scanner.
- Identity. Sign-in logs for the identity provider show which applications people actually use; OAuth grants reveal what has been given access to corporate data.
- DNS and egress. Outbound requests to cloud consoles and API endpoints.
- Certificates and passive DNS, for anything published under your domains.
- Cloud billing, which knows about accounts that no inventory does.
What to do with it
Decide per asset: adopt (bring it under management), migrate (move the function into a supported platform) or remove. Adoption needs to be genuinely easy or the cycle repeats.
The durable fix is a paved path: a quick, documented way to get a project, a domain, a cloud account or a tool with sensible defaults already applied. Shadow IT is a routing problem, and routing problems are solved by better roads rather than more signs.