Managed IT Support
What is shadow IT? Why staff build their own systems and how to find them
Shadow IT explained for UK businesses: why staff build workarounds outside approved systems, the security and data risks, and how to discover and manage it.
By Dig IT SolutionsUpdated 8 September 20265 min read
Short answer
Shadow IT is any software, cloud service, device or home-made system used for work without the knowledge or approval of whoever manages the business's IT. It usually appears because the official system is slow or awkward. The risks are uncontrolled data, unmanaged security and single-person dependencies. Microsoft 365 app reports and expense reviews find most of it.
Every business has it. The spreadsheet that quietly became the customer database. The WhatsApp group where the real job updates happen. The free tool a manager signed up to with their work email because the approved system could not produce the report they needed. Shadow IT is what staff build when technology does not do what their job requires, and it is usually a sign of a problem with the official systems rather than with the people. This guide covers why it happens, why it matters and, most usefully, how to find it.
What shadow IT is
Shadow IT is any technology used for work without the knowledge or approval of whoever manages IT. In a business of up to 250 people it typically looks like:
- personal cloud storage (Dropbox, Google Drive, iCloud) holding work files
- messaging apps used for client or operational communication
- department spreadsheets and Access databases that have become systems of record
- free or trial cloud tools connected to Microsoft 365 with a work login
- paid SaaS subscriptions bought on a company card without IT involvement
- personal laptops, phones and home printers used for work
- automation scripts or macros only their author understands
It rarely announces itself. Most shadow systems run for months or years before anyone outside the team knows they exist.
Why staff build their own systems
People do not create workarounds out of defiance. They do it to get their work done. The common triggers are:
The official system is slow. Entering an order takes five minutes through the approved platform and thirty seconds in a spreadsheet. Speed wins, every time.
The system does not match how the work is done. Generic software meets generic needs. A team with a specific reporting requirement the CRM cannot meet will build the report somewhere else.
The system is unpleasant to use. Every extra click and confusing screen adds friction, and friction pushes people towards whatever is easier.
Nobody was trained. A surprising amount of shadow IT duplicates features the official system already has. Staff assumed the capability did not exist because nobody showed them.
They asked and nothing happened. Once a request for a fix has gone unanswered a couple of times, people stop asking and start building.
The pattern to notice is that all of these are failures of the official environment or the process around it. Fixing them removes the demand for workarounds far more effectively than banning the workarounds.
Why it matters
Data leaves controlled systems. A customer list in a personal Dropbox has no company backup, no MFA you control, no sharing audit and no way to wipe it when the employee leaves. If it contains personal data, it is still your responsibility under UK GDPR. The ICO's expectations for organisations are set out at ico.org.uk/for-organisations.
Security is unmanaged. Unapproved apps connected to Microsoft 365 may have been granted permission to read mail and files. Personal devices have no endpoint protection or patching. The business's cyber security controls only cover what the business knows about.
Records conflict. When the same information lives in the CRM and in three spreadsheets, none of them is right. Reports disagree, decisions are made on stale data and time is spent reconciling.
Processes depend on one person. The spreadsheet with the macros works until its author leaves. Then a critical process stops and nobody knows how it worked. This is one of the most common continuity failures in small businesses.
Costs hide. Subscriptions on individual cards, each small, add up across a company and duplicate tools already paid for.
How to find it
Guesswork does not work. These five steps surface most shadow IT within a couple of weeks.
1. Review app consents in Microsoft 365. In the Microsoft Entra admin centre, open Enterprise Applications and look at everything users have consented to. Each entry is a third-party service with some level of access to your tenant. Check the permissions granted, and remove anything unrecognised or over-privileged. Then set user consent settings so that future apps require admin approval. Microsoft's documentation is at learn.microsoft.com/microsoft-365.
2. Use cloud app discovery. Microsoft Defender for Cloud Apps (included in Business Premium) analyses traffic from managed devices and the firewall and lists the cloud services actually in use, with risk scores. Businesses are routinely surprised by the length of the list.
3. Review SaaS spend with finance. Go through six months of expense claims and card statements for software subscriptions. Compare against the approved list. This finds the paid shadow IT that discovery tools miss because it is used on the web.
4. Check firewall and DNS logs. A business firewall with web filtering, or a DNS filtering service, shows which cloud services are being reached from the office network. Look for file-sharing, messaging and storage services that are not yours.
5. Ask the teams. A short, no-blame conversation with each department: what do you use that is not on the list, and why? This is the step that explains the results of the other four, and it is where the fixes come from.
What to do once you have found it
Resist the urge to switch everything off. Sort what you find into three groups:
- Formalise: workarounds that solve a real gap. Bring the spreadsheet into SharePoint with proper access control and backup, or replace it with the feature in the official system that nobody knew about.
- Replace: tools doing a job the business needs, but in a risky way. A team using personal Dropbox needs a properly structured SharePoint library, not a lecture.
- Retire: duplicate subscriptions and services with no remaining purpose. Cancel them and remove the app consents.
Then close the routes that made it easy. Require admin approval for new app consents, remove local admin rights so software cannot be installed freely, apply conditional access so company data is only reachable from managed devices, and publish a short approved-tools list with a request process that answers within the week.
Finally, fix the underlying complaints. If the CRM is too slow, that is a support ticket, not a reason to tolerate a parallel database. A managed IT provider who reviews ticket trends will see the pattern before it becomes shadow IT.
Culture is the long-term fix
The businesses with the least shadow IT are not the ones with the strictest controls. They are the ones where staff believe that reporting a problem will get it fixed, where new tools can be requested and approved quickly, and where nobody is blamed for having built a workaround. Treat the people who built shadow systems as the ones who understand where the official systems fall short, because they are.
What to do next
If you have never reviewed your Microsoft 365 app consents or compared your subscription spend against what IT knows about, there is almost certainly shadow IT in the business. Dig IT's IT health check includes a cloud app and access review for organisations across Hertfordshire, west Essex and London, and ends with a plan for what to formalise, replace and retire.

