Skip to main content
Dig IT Solutions logo

Managed IT Support

What is shadow IT? Why staff build their own systems and how to find them

Shadow IT explained for UK businesses: why staff build workarounds outside approved systems, the security and data risks, and how to discover and manage it.

By Dig IT SolutionsUpdated 8 September 20265 min read

Short answer

Shadow IT is any software, cloud service, device or home-made system used for work without the knowledge or approval of whoever manages the business's IT. It usually appears because the official system is slow or awkward. The risks are uncontrolled data, unmanaged security and single-person dependencies. Microsoft 365 app reports and expense reviews find most of it.

Every business has it. The spreadsheet that quietly became the customer database. The WhatsApp group where the real job updates happen. The free tool a manager signed up to with their work email because the approved system could not produce the report they needed. Shadow IT is what staff build when technology does not do what their job requires, and it is usually a sign of a problem with the official systems rather than with the people. This guide covers why it happens, why it matters and, most usefully, how to find it.

What shadow IT is

Shadow IT is any technology used for work without the knowledge or approval of whoever manages IT. In a business of up to 250 people it typically looks like:

  • personal cloud storage (Dropbox, Google Drive, iCloud) holding work files
  • messaging apps used for client or operational communication
  • department spreadsheets and Access databases that have become systems of record
  • free or trial cloud tools connected to Microsoft 365 with a work login
  • paid SaaS subscriptions bought on a company card without IT involvement
  • personal laptops, phones and home printers used for work
  • automation scripts or macros only their author understands

It rarely announces itself. Most shadow systems run for months or years before anyone outside the team knows they exist.

Why staff build their own systems

People do not create workarounds out of defiance. They do it to get their work done. The common triggers are:

The official system is slow. Entering an order takes five minutes through the approved platform and thirty seconds in a spreadsheet. Speed wins, every time.

The system does not match how the work is done. Generic software meets generic needs. A team with a specific reporting requirement the CRM cannot meet will build the report somewhere else.

The system is unpleasant to use. Every extra click and confusing screen adds friction, and friction pushes people towards whatever is easier.

Nobody was trained. A surprising amount of shadow IT duplicates features the official system already has. Staff assumed the capability did not exist because nobody showed them.

They asked and nothing happened. Once a request for a fix has gone unanswered a couple of times, people stop asking and start building.

The pattern to notice is that all of these are failures of the official environment or the process around it. Fixing them removes the demand for workarounds far more effectively than banning the workarounds.

Why it matters

Data leaves controlled systems. A customer list in a personal Dropbox has no company backup, no MFA you control, no sharing audit and no way to wipe it when the employee leaves. If it contains personal data, it is still your responsibility under UK GDPR. The ICO's expectations for organisations are set out at ico.org.uk/for-organisations.

Security is unmanaged. Unapproved apps connected to Microsoft 365 may have been granted permission to read mail and files. Personal devices have no endpoint protection or patching. The business's cyber security controls only cover what the business knows about.

Records conflict. When the same information lives in the CRM and in three spreadsheets, none of them is right. Reports disagree, decisions are made on stale data and time is spent reconciling.

Processes depend on one person. The spreadsheet with the macros works until its author leaves. Then a critical process stops and nobody knows how it worked. This is one of the most common continuity failures in small businesses.

Costs hide. Subscriptions on individual cards, each small, add up across a company and duplicate tools already paid for.

How to find it

Guesswork does not work. These five steps surface most shadow IT within a couple of weeks.

1. Review app consents in Microsoft 365. In the Microsoft Entra admin centre, open Enterprise Applications and look at everything users have consented to. Each entry is a third-party service with some level of access to your tenant. Check the permissions granted, and remove anything unrecognised or over-privileged. Then set user consent settings so that future apps require admin approval. Microsoft's documentation is at learn.microsoft.com/microsoft-365.

2. Use cloud app discovery. Microsoft Defender for Cloud Apps (included in Business Premium) analyses traffic from managed devices and the firewall and lists the cloud services actually in use, with risk scores. Businesses are routinely surprised by the length of the list.

3. Review SaaS spend with finance. Go through six months of expense claims and card statements for software subscriptions. Compare against the approved list. This finds the paid shadow IT that discovery tools miss because it is used on the web.

4. Check firewall and DNS logs. A business firewall with web filtering, or a DNS filtering service, shows which cloud services are being reached from the office network. Look for file-sharing, messaging and storage services that are not yours.

5. Ask the teams. A short, no-blame conversation with each department: what do you use that is not on the list, and why? This is the step that explains the results of the other four, and it is where the fixes come from.

What to do once you have found it

Resist the urge to switch everything off. Sort what you find into three groups:

  • Formalise: workarounds that solve a real gap. Bring the spreadsheet into SharePoint with proper access control and backup, or replace it with the feature in the official system that nobody knew about.
  • Replace: tools doing a job the business needs, but in a risky way. A team using personal Dropbox needs a properly structured SharePoint library, not a lecture.
  • Retire: duplicate subscriptions and services with no remaining purpose. Cancel them and remove the app consents.

Then close the routes that made it easy. Require admin approval for new app consents, remove local admin rights so software cannot be installed freely, apply conditional access so company data is only reachable from managed devices, and publish a short approved-tools list with a request process that answers within the week.

Finally, fix the underlying complaints. If the CRM is too slow, that is a support ticket, not a reason to tolerate a parallel database. A managed IT provider who reviews ticket trends will see the pattern before it becomes shadow IT.

Culture is the long-term fix

The businesses with the least shadow IT are not the ones with the strictest controls. They are the ones where staff believe that reporting a problem will get it fixed, where new tools can be requested and approved quickly, and where nobody is blamed for having built a workaround. Treat the people who built shadow systems as the ones who understand where the official systems fall short, because they are.

What to do next

If you have never reviewed your Microsoft 365 app consents or compared your subscription spend against what IT knows about, there is almost certainly shadow IT in the business. Dig IT's IT health check includes a cloud app and access review for organisations across Hertfordshire, west Essex and London, and ends with a plan for what to formalise, replace and retire.

Frequently asked questions

What are common examples of shadow IT in a small business?
Personal Dropbox or Google Drive accounts holding work files, a WhatsApp group used for client updates, a department spreadsheet that has become the real customer database, free trial tools connected to Microsoft 365 with a work login, a personal laptop used for work over the weekend, and paid subscriptions bought on a company card that IT has never heard of.
Is shadow IT always a bad thing?
No. It is almost always a signal that an official system is failing someone, and the workaround often solves a genuine problem. The risk is in what surrounds it: no backup, no access control, no MFA, data outside the systems covered by your UK GDPR obligations, and a process that only one person understands. The right response is to find it, understand why it exists and bring it under control, not to punish the person who built it.
How do I find shadow IT in Microsoft 365?
In the Entra admin centre, review Enterprise Applications to see every third-party app users have consented to, and the sign-in logs for unfamiliar services. Microsoft Defender for Cloud Apps, included with Business Premium, discovers cloud services in use from firewall and endpoint traffic. Also check OneDrive and SharePoint sharing reports for links to personal email addresses.
How does shadow IT affect UK GDPR compliance?
Personal data in unapproved systems is still personal data you are responsible for, but you cannot demonstrate control over it, delete it on request, or include it in a breach assessment if you do not know it exists. The ICO expects organisations to know where personal data is held. Shadow IT makes that impossible to answer honestly.
Should we block staff from installing apps or connecting services?
Partly. Restricting user consent for third-party apps in Microsoft 365, and removing local admin rights on laptops, removes the easiest routes. But blocking without providing an approved alternative and a quick way to request tools just pushes the workaround somewhere less visible. Pair the controls with a short approved-tools list and a same-week request process.
What is the first step to reducing shadow IT?
Ask. A short, no-blame conversation with each team about what they use that is not on the official list, and why, surfaces most of it faster than any tool. Then fix the underlying frustration where you can, formalise the useful workarounds, and retire the risky ones with a proper replacement.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us