The average 50-person Melbourne SME has 60 to 80 SaaS apps in use. Finance can see maybe 15 of them. The rest were signed up to by individual staff on free trials or personal credit cards. The fix is discovery, triage and a clear sanctioning path, not a memo telling people to stop.
Why shadow IT happens (and why blaming users is the wrong move)
Before we talk discovery, it is worth being honest about why shadow IT exists. Three reasons account for almost all of it.
The first is speed. The official process for getting a new SaaS tool approved at most Melbourne SMEs is “raise a request, wait two weeks, get told no”. Trello is free. Notion is free. Calendly is free. ChatGPT is free. A salesperson who needs to send a polished proposal to a prospect by Friday will not wait two weeks. They will sign up for the free tier on Wednesday and put the paid upgrade through their personal card if the trial expires before they have proven the case for an official tool.
The second is feature gaps. Microsoft 365 is excellent at a lot of things and mediocre at a few. Planner is not Trello. Forms is not Typeform. SharePoint document collaboration is not Notion. When the official toolset has a feature shaped hole, staff fill it from outside. It is common to find an accounting firm running three separate Notion workspaces precisely because nobody could agree whether SharePoint or Teams was the right place to do running notes.
The third is autonomy. Department heads, particularly in sales and marketing, often have their own budget and the authority to spend it. They are not breaking any rules when they sign up to HubSpot, Mailchimp, Canva Pro or Loom. They are exercising the budget authority they were given. IT only finds out when something integrates badly with the core stack, or when the credit card runs through to finance.
The right framing is: shadow IT is a signal that your official tooling is missing something. Treat it as feedback, not as misbehaviour.
The actual cost of unsanctioned SaaS
Shadow IT is not free for the business. It costs in five distinct ways.
Direct duplication. Three different teams each paying $50 a month for the same tool because none of them knows the others have it. It is not unusual to find an SME paying for Slack, Microsoft Teams, Google Chat and Discord simultaneously. None of the leaders knew about all four.
Data exposure. Client data in unmanaged tools the business has no idea exists, with no DLP, no retention policy, and no offboarding when the staff member leaves. The Notion workspace tied to someone’s personal email survives their departure indefinitely unless someone goes looking.
Compliance failure. The Australian Privacy Act obligations apply to personal information regardless of which SaaS tool the staff member chose to store it in. The fact that the tool was not sanctioned by IT is not a defence. The 2024-25 amendments tightened the breach notification and accountability requirements specifically here.
Integration risk. Every shadow tool that connects to Microsoft 365 via OAuth gets a slice of access to your tenant. Most of them are fine. Some of them are not. There is a non-trivial number of “free productivity apps” with read access to mailbox content.
Exit friction. When a senior staff member leaves and they have been the de facto owner of three shadow SaaS tools the rest of the team relies on, you are now in the position of either paying ransom to get the data out, or rebuilding the institutional knowledge from scratch.
Four discovery methods that actually work for SMEs
You do not need to buy a Cloud Access Security Broker for $40,000 a year to find your shadow IT. There are four cheap and effective methods, and the right answer for most Melbourne SMEs is to run all four sequentially.
Method 1: Microsoft Defender for Cloud Apps (if you have it)
If you are on Microsoft 365 E5, Defender for Cloud Apps is built in. If you are on Business Premium, it is not, but the related “Cloud Discovery” features in Microsoft Defender for Endpoint give you a surprisingly useful subset. Both work by analysing endpoint and firewall logs for outbound connections to known SaaS providers, then producing a discovery report that maps which staff are using what.
The first run of this against a tenant is always sobering. Run it against a 70-person firm and a discovery report listing well over 100 distinct cloud services, of which a dozen are formally sanctioned, is a normal result. The rest broke down into “harmless free tools nobody minds” (about 80), “duplicates of things we already pay for” (about 20), “things that should probably be replaced” (about 15), and “wait what is this” (about 10).
Defender for Cloud Apps gives you a risk score per service based on a published catalogue of about 30,000 cloud apps with their compliance and security attributes. That risk score is a useful starting point for triage but should not be treated as the final word.
Method 2: Expense report keyword scan
This costs nothing. Export the last twelve months of corporate card transactions and personal expense reimbursements. Scan for the obvious keywords: Notion, Trello, Asana, Monday, Loom, Calendly, Canva, HubSpot, Mailchimp, ChatGPT, Anthropic, OpenAI, Zapier, Make, Airtable, Slack, Zoom, Lucidchart, Miro, Figma, Dropbox, Google. Add any local Australian SaaS providers relevant to your industry.
This catches everything that has gone through finance, which is roughly two-thirds of all shadow IT, in our experience. The expense report scan is fast, cheap, and produces a list with names attached, which is the part that makes the conversation possible. A salesperson cannot deny they signed up to HubSpot when the $80 a month is on their May expense report.
We did this exercise for a Geelong construction firm and the keyword scan caught more shadow SaaS than the Defender for Cloud Apps discovery did, because so much of the spend was on personal cards being expensed back.
Method 3: Browser extension audit
If your staff use Chrome or Edge on managed devices, the installed extensions list is a goldmine of shadow tooling. Grammarly, Loom, Asana, Notion Web Clipper, ChatGPT extensions, password manager extensions that are not the corporate one, screen recorders, AI writing assistants, they all show up.
This is also where you find the genuinely risky stuff. There is a long tail of malicious browser extensions that survive on the Chrome Web Store for weeks at a time before being pulled, often with names that look like productivity tools. An extension audit catches these and is also a chance to enforce an allowlist via Microsoft Edge for Business or Chrome Enterprise policies.
For Melbourne SMEs on Microsoft Intune, this is a one-page report. For unmanaged endpoints it requires a walk-the-floor approach, which is part of why endpoint management matters.
Method 4: Microsoft 365 OAuth consent report
This is the one most people miss. Every time a staff member clicks “Sign in with Microsoft” on a third-party SaaS app, that app gets an OAuth token to access some scope of their Microsoft 365 data. The list of apps with active OAuth consent against your tenant lives in the Entra admin centre under Enterprise Applications, and is usually astonishing the first time someone looks.
We did this for a Camberwell architecture firm and found 89 third-party applications with active OAuth consent against their tenant, including three that had been granted “read all mail” scope, one of which was a free email tracking tool an account manager had signed up to in 2022 and forgotten about. That OAuth grant survived their staff turnover and was still active two years later.
The OAuth consent report is also where you find the AI integrations. ChatGPT plugins, Anthropic Claude connections, Zapier OAuth grants, all the new wave of AI productivity tools that are wiring themselves into Microsoft 365. None of them are inherently malicious. All of them deserve to be looked at.
The four-bucket triage: sanction, replace, retire, ignore
Once you have a discovery list, every item goes into one of four buckets. The bucket determines the action. This is the framework we use with every Melbourne SME shadow IT engagement.
| Bucket | What it means | Action | Typical examples |
|---|---|---|---|
| Sanction | Genuinely useful, no reasonable alternative in the existing stack, acceptable risk profile | Bring under IT management, move billing to the corporate card, document data classification, set up offboarding workflow | Specialist design tools, niche industry apps, accepted general productivity tools (Calendly, Loom) |
| Replace | Duplicates a capability the business already pays for elsewhere | Migrate users to the official tool, cancel the shadow subscription, set a hard date | Trello when the org pays for Planner, Dropbox when the org pays for OneDrive, Slack when the org pays for Teams |
| Retire | Genuinely risky, dormant, abandoned, or actively dangerous | Revoke OAuth grants, contact provider for data export, then delete | Forgotten OAuth grants from 2022, malicious browser extensions, abandoned personal accounts holding client data |
| Ignore | Low risk, low cost, low value to act on | Note it, move on, do not waste cycles | Free productivity tools with no data sharing, personal-use tools, ad-hoc utilities |
The ignore bucket is important. The temptation in shadow IT projects is to try to bring everything under formal control, which is both impossible and counterproductive. If a salesperson has Grammarly installed on their personal browser profile and uses it occasionally, that does not need to be on a vendor management register. Pick your battles.
Worked example: an accounting firm with three Trellos
Consider an illustrative mid-sized accounting firm, about 60 staff across two offices, that runs a shadow IT discovery exercise because its cyber insurer has started asking pointed questions about SaaS inventory at renewal. The findings were instructive.
The expense report scan turned up three separate Trello accounts run by three different teams. None of the teams knew the others had one. Each was paying $13 per user per month for the standard tier. The combined annual spend was $14,400, and the equivalent functionality was already available in Microsoft Planner and Loop, which were included in their existing M365 Business Premium subscription.
The OAuth consent report identified two Notion workspaces with active access to mailbox content. One was being actively used by the marketing team; the other belonged to a partner who had set it up in 2023 to draft a strategy document and then forgotten about it. The forgotten one still had read access to his mailbox via OAuth.
Most concerning, the browser extension audit identified a competitor’s project management tool, a SaaS aimed at accounting firms specifically, installed by a junior accountant on her work laptop. She had been adding live client data into it as a personal productivity tool because she found it easier than the firm’s official practice management software. The client data exposure was real, the staff member’s intent was harmless, and the underlying problem was that the official tool was genuinely worse than the alternative she found.
The triage outcome: Trellos consolidated and replaced with Planner over six weeks. The active Notion workspace was sanctioned and brought under IT management with proper offboarding workflow. The forgotten one was retired and OAuth revoked. The competitor tool was retired, the data was migrated out and into the firm’s official system, and the practice management software was put on the roadmap for replacement because the staff feedback was now formally on the table. None of this would have happened without the discovery exercise.
Building a sanctioning path so this does not happen again
Discovery is the first step. The longer-term fix is to build an internal path for staff to legitimately request new SaaS tools, with a turnaround time fast enough that they do not need to go around it. Three principles.
Time-box the approval. Five business days from request to yes/no. Longer than that and people will revert to shadow IT. The five-day commitment is enforceable if the assessment is structured: data classification, vendor security posture, integration impact, cost. A senior engineer can usually run this in two hours.
Pre-approve common categories. Maintain a list of SaaS categories where any tool from a pre-approved shortlist can be self-served by staff. Design tools, video conferencing, scheduling tools, none of these need a full assessment every time someone wants to use one. The shortlist gets reviewed quarterly.
Make rejection mean something. If you say no to a tool, you owe the requester either an alternative that meets their need or a clear explanation of why the problem cannot be solved that way. “No” without context is what drives staff into the shadow IT cycle. Co-managed IT models often work well here because they give internal IT the capacity to run this assessment without becoming the bottleneck.
The role of identity and conditional access
Shadow IT discovery is closely related to the broader identity story. The more you centralise authentication through Microsoft Entra ID, the more visibility you get over what is connected to your tenant. Tools that require staff to create separate accounts with personal email addresses are inherently invisible; tools that integrate via “Sign in with Microsoft” show up in the OAuth consent report.
Conditional Access policies can be configured to require admin consent for any new third-party application requesting Microsoft 365 data access, which closes the OAuth-grant-from-2022 problem at the source. This is one configuration change, takes about thirty minutes, and stops new shadow IT from accumulating in that specific way. We make it a standard part of the cybersecurity baseline for every new client tenant we onboard.
The trade-off is that admin consent becomes a queue you have to service. If the queue is slow, staff will route around it. Five business days, again.
What this costs to fix
For a typical 50-person Melbourne SME, a complete shadow IT discovery and triage engagement runs four to six weeks of elapsed time and one to two days of senior engineer effort. The deliverables are: an inventory of cloud services in use, a triage report with recommended actions per service, a remediation plan for the high-risk items, and a sanctioning workflow design for ongoing requests.
The hard-dollar return varies but is almost always positive. The Geelong construction firm saved $9,400 a year in duplicate SaaS subscriptions identified during discovery. The Richmond legal firm saved closer to $22,000 because they had been paying for three project management tools and four file-sharing tools simultaneously. In that scenario the firm breaks even on direct cost but eliminates a data exposure that would have been a notifiable breach if it had been discovered later.
The softer return, the reduction in compliance risk, the cleaner OAuth surface, the ability to answer “what SaaS tools do you use” honestly on an insurance renewal, is harder to put a number on but matters more.
How TechAssist runs shadow IT discovery
We treat shadow IT discovery as a structured engagement, not an ongoing service. The work is intensive for four to six weeks and then transitions into a steady-state sanctioning process that internal stakeholders can run themselves with our support.
We have 13 Melbourne-employed staff, a NOC in Tecoma and 24/7 on-call and emergency support. Our two offices, Tecoma and Bourke Street CBD, let us run on-site sessions for Melbourne metro clients on the same business day where the discovery work needs human follow-up. Our practice is Essential Eight aligned, which matters when the deliverable from the engagement needs to land in front of an auditor or cyber insurer.
The method is the same whether the business is in construction, manufacturing, logistics, law, accounting or healthcare. The methodology is broadly similar; the specific tools that show up vary wildly by industry. A construction firm’s shadow IT is almost entirely site-management apps and free file-sharing tools. A law firm’s is document collaboration and AI drafting tools. A healthcare provider’s is patient communication platforms, which is where the regulatory stakes get serious.
Frequently Asked Questions
Is shadow IT really a security problem or just an IT housekeeping issue?
Both, depending on which tool. A free Calendly account with no client data in it is housekeeping. A Notion workspace holding client matter notes with OAuth access to a partner’s mailbox is a security problem. The point of discovery and triage is to tell the difference and act accordingly.
Can we just ban shadow IT outright?
You can write a policy that says so, but you cannot enforce it without either heavy egress controls (which most SMEs find impractical) or a fast sanctioning process (which most do not have). The realistic answer is “discover, triage, sanction the useful, retire the risky, build a fast path for new requests so people use it”.
How often should we run a discovery exercise?
The first run is the big one. After that, an annual refresh combined with a quarterly OAuth consent review is enough for most Melbourne SMEs. If your business is going through rapid headcount growth or a significant tooling change, run discovery more often.
Do free SaaS tools count as shadow IT?
Yes. The pricing is irrelevant to the risk assessment. A free Trello account with client tasks in it is the same data exposure problem as a paid one. The triage matters more than the cost.
What about staff using their personal ChatGPT account for work?
This is the 2026 version of the shadow IT problem and it deserves its own conversation. Personal AI accounts in use for work tasks need to be either replaced with sanctioned enterprise alternatives (Microsoft 365 Copilot Chat, ChatGPT Team, Anthropic Claude Team) or actively prohibited. The middle ground, “just be careful”, does not work because there is no audit trail.
Should we tell staff we are running discovery?
Yes. Transparency makes the exercise work better. Staff who know discovery is happening volunteer information that the technical methods would not have caught. Frame it as “we want to make sure the tools you need are properly supported”, not as “we are looking for who broke the rules”.
What to do this week
Pick one of the four discovery methods and run it. The expense report scan is the easiest starting point and requires nothing more than a spreadsheet and an hour. The OAuth consent review is the second easiest if you have Microsoft 365 admin access. Both will turn up enough to justify a broader conversation.
Whatever you find, do not lead with blame. Lead with curiosity. The staff who signed up for these tools were trying to do their jobs. The fix is to build a system where doing their jobs and following the rules are the same thing.
If you want a hand running a structured shadow IT discovery and triage across your Melbourne business, get in touch. We will tell you what is worth fixing and what is not.
