The 2026 Guide to Uncovering Unsanctioned Cloud Apps
If your goal is to identify unsanctioned cloud applications, looking at written policies alone will not give you the full picture. Start by examining how your employees actually work online.
The technology environment inside a modern business often looks very different from the official list maintained by IT. Employees may adopt a free application to complete a task more quickly, create a personal file-sharing account for convenience, install a browser extension to meet a deadline or activate an AI capability that has been added to an existing business platform.
Each decision may seem harmless when viewed individually.
The problem emerges when these choices accumulate. Company information can end up distributed across services that have never gone through a security review, user accounts that are difficult to manage and sharing configurations that were never designed for business use.
Finding these applications is therefore only the first step. Organizations also need a practical way to understand the associated risk and determine what should happen next.
Why Unsanctioned Cloud Apps Matter in 2026
Employees have been using unapproved cloud services for years. What makes the issue more pressing in 2026 is the combination of rapid adoption, a growing number of available services and AI capabilities becoming part of applications employees already use.
The scale alone can be surprising.
According to Microsoft's shadow IT guidance, organizations often estimate that their employees use around “30 or 40” cloud applications. In practice, the average organization may have “over 1,000 separate apps.”
Microsoft also reports that “80% of employees use non-sanctioned apps” that have not been evaluated against organizational policies. This highlights a significant visibility gap between an organization's approved software inventory and the applications employees actually access.
AI adds another layer to the problem.
Employees do not always need to sign up for a dedicated AI service to introduce AI-related risk. The Cloud Security Alliance points out that AI capabilities are increasingly being built directly into common business applications.
That means an organization may unknowingly have AI processing business information through an application that was previously considered routine.
The same Cloud Security Alliance resource cites research indicating that “54% of employees” would use AI tools without company authorization. It also references IBM research reporting that “20% of organizations” experienced breaches associated with unauthorized AI use, with those incidents adding an average of “$670,000” to breach costs.
The issue therefore extends beyond software governance. Unmanaged cloud applications can create tangible security and financial exposure.
There is also a practical limitation to relying on blanket restrictions. Cloud applications are now deeply integrated into everyday business operations. As the Cloud Security Alliance explains, simply blocking cloud services is no longer a realistic strategy. If employees cannot access an approved solution that meets their needs, they may look elsewhere.
Why Blocking Everything Is the Wrong Starting Point
Immediately banning every unapproved application may seem like the simplest solution. In practice, it can make visibility worse.
Employees who depend on a particular application may attempt to work around the restriction rather than abandon the workflow. They may also move to another service that has not been evaluated and could present an even greater security concern.
The result is often the same problem with less visibility.
Instead, begin by determining which services are being used, how they are being used and what business need they address.
The Cloud Security Alliance recommends evaluating cloud activity against an “objective yardstick”. Looking at actual user behavior gives security teams more useful information than simply judging an application based on its name.
Once usage and risk are understood, organizations can make more targeted decisions.
Some applications may meet security requirements and can be formally approved. Others may remain available with specific restrictions. Certain workflows may be better moved to approved alternatives.
Applications presenting serious and unmanaged risks can then be blocked deliberately, with users given advance notice and a viable replacement wherever possible.
A Practical Process for Finding Unsanctioned Cloud Apps
Cloud application discovery should not be treated as a one-off cleanup exercise. New services, integrations and employee workflows appear continuously, so organizations should repeat the process regularly, such as quarterly, or use continuous monitoring where appropriate.
Discover the Applications Employees Actually Use
Begin with data sources that already provide insight into user activity.
Depending on your environment, these may include:
- Endpoint and device telemetry
- Identity and authentication logs
- Network and DNS activity
- Browser activity
- SaaS administration records
The Microsoft shadow IT guidance emphasizes the importance of discovering cloud applications before attempting to govern them. Without a reliable inventory, security teams have limited visibility into what needs to be reviewed.
Examine How Those Applications Are Being Used
An application inventory by itself does not tell you how much risk a particular service creates.
Look at usage patterns such as:
- Which employees or departments access the application
- What administrative functions are being performed
- Whether company information is shared publicly
- Whether employees are using personal accounts
- Whether former employees or inactive accounts still have access
- What types of business information are being uploaded or exchanged
This additional context helps distinguish occasional low-risk use from activity that could expose sensitive business information.
Evaluate and Rank the Risk
Avoid treating every unsanctioned application as equally dangerous.
Instead, assess each one using a consistent set of criteria, including:
- Sensitivity of the information involved
- How and with whom data is shared
- Strength of authentication and identity controls
- Visibility available to administrators
- Data retention and handling practices
- Presence of AI features that may process organizational information
A simple scoring framework makes it easier to focus resources on applications with the greatest potential impact.
Classify the Applications
Once applications have been assessed, assign clear labels so their status is easy to understand and manage.
Microsoft highlights the value of identifying applications as sanctioned or unsanctioned. This type of classification makes it easier to filter applications, monitor changes and apply consistent governance measures.
Your organization could use categories such as:
- Sanctioned: Reviewed and approved for business use.
- Restricted: Permitted only under defined conditions.
- Under Review: Identified but awaiting a formal risk decision.
- Unsanctioned: Not approved for business use.
- Blocked: Access is prohibited because the associated risk cannot be adequately managed.
The exact labels can vary, but consistency is what matters.
Apply the Appropriate Response
Classification should lead to a clear action.
Microsoft's governance guidance describes options such as notifying users when an application presents a concern or blocking access when the associated risk is unacceptable.
Warnings can be useful when the issue can be addressed through better user behavior. Blocking may be appropriate when an application presents significant exposure and no reasonable controls are available.
Before making major changes, consider how employees currently depend on the service. Communicate the decision, explain the reason and, when possible, provide an approved alternative.
This reduces the likelihood that users simply migrate to another unmanaged application.
Make Discovery, Decision and Enforcement Routine
Unsanctioned cloud applications are unlikely to disappear. As cloud software becomes more embedded in business operations and AI capabilities continue appearing inside everyday platforms, the number of applications organizations need to monitor may continue to grow.
The answer is not necessarily to prohibit every unfamiliar service.
A more sustainable model is to establish a recurring process:
Discover → Assess → Classify → Decide → Enforce
First, determine what employees are actually using. Then evaluate the associated data and security risks. Assign each application a clear status and take an appropriate action based on that assessment.
When this process becomes part of routine security operations, cloud application sprawl becomes easier to manage. Instead of discovering unknown services only after an incident, your organization gains an ongoing view of its cloud environment and can respond before small gaps become larger problems.
If you need assistance developing a practical cloud application governance program, contact us today. We can help identify unsanctioned services, evaluate potential exposure and establish sensible controls that protect your environment without unnecessarily disrupting day-to-day productivity.