Overig · Overig
Shadow IT: the invisible risk of poor Identity & Access Management

Dylan Klümann · 10 min read
The silent threat within organisations
Most organisations invest heavily in firewalls, endpoint security, and network protection. Yet a significant risk often lies not within the IT department itself, but in employee work habits. Shadow IT, the use of non-approved applications and tools – is growing faster than ever. Often with the best intentions, but with major consequences for security, compliance, and business continuity.
In this blog we explain:
What Shadow IT is and why it arises
What risks are associated with it
How Joinly provides a solution
How Entra ID and Active Directory play a key role in this
What is Shadow IT?
Shadow IT occurs when employees use applications or cloud services without IT department approval. Consider:
A Dropbox account to quickly share files
A Trello or Asana board for project management
ChatGPT or other AI tools where sensitive data is entered
Personal Gmail accounts to send company information
The reason is almost always practical: employees want to work faster, access user-friendly tools, or simply get their work done without bureaucratic processes. It sounds harmless, but the consequences are often significant.
Why do employees turn to Shadow IT?
Employees mainly turn to Shadow IT when official processes are too slow or when the application landscape within the organisation doesn't sufficiently meet their needs. Many tools available online feel simpler than what is offered internally. Moreover, many employees don't realise that their ‘quick solution’ simultaneously poses a security risk. Shadow IT is therefore rarely the result of malicious behaviour, but rather of efficiency and frustration.
It is rarely about malicious behaviour, but about frustration or efficiency.
The risks of Shadow IT
The risks arising from this are diverse. Sensitive information may end up in unsecured applications, potentially leading to data breaches. For organisations that must comply with standards like ISO 27001 or GDPR, Shadow IT presents significant challenges because it's unclear where data resides. The lack of monitoring and logging also complicates audits and incident response. Furthermore, former employees might still have access to personally chosen tools never included in the official account system. Add to that uncontrolled subscriptions quickly drive up costs, and the impact of Shadow IT is complete.
Joinly as a response to Shadow IT
The solution is not to ban tools or punish employees. Shadow IT is a symptom of a lack of good Identity & Access Management. IAM can steer employee behaviour positively. It works as follows:
HR-driven provisioning
New employees automatically receive the correct access rights from day one, based on their role. No more frustration due to missing tools.
Single Sign-On (SSO)
Direct access to all approved applications with one set of login credentials. This makes the user experience comparable to the ‘quick solution’ of Shadow IT.
Self-service access
Employees can request additional applications themselves through a controlled workflow. Access is automatically approved and set up, without administrative hassle.
Automatic deprovisioning
When someone leaves, all rights are immediately withdrawn. This prevents former employees from maintaining access to systems.
The role of Entra ID and Active Directory
Many organisations still use Active Directory (AD) as the backbone of their identity management. AD is strong in on-premise environments but less suited to the cloud world. This is where Microsoft Entra ID (formerly Azure AD) comes into play.
Active Directory (AD)
Suitable for on-premises networks
Manages traditional accounts, printers, servers, and workstations
Strong in Windows environments
Entra ID
Designed for cloud and hybrid work setups
Supports thousands of SaaS applications (Microsoft 365, Salesforce, etc.)
Offers advanced features such as Conditional Access and Identity Governance
The strength lies in the combination: organisations that cleverly integrate AD and Entra ID gain a unified overview of identities, both for on-premise and cloud. This reduces the likelihood of employees turning to external tools.
Real-world example
A new employee starts at an organisation. Without IAM, it takes days before he has access to the HR application, the CRM system, and the internal knowledge base. Out of frustration, he starts storing documents in his personal Google Drive and uses a free trial of Slack to communicate with colleagues.
With Joinly it’s very different: the HR system automatically creates an account, Joinly links this to AD and Entra ID, and within minutes the employee has access to everything he needs via SSO. Access to other applications is set up via RBAC or ABAC. A detailed explanation of what this entails can be found here: https://joinly.app/blog/rbac-vs-abac-who-gets-the-key-to-your-digital-home
Result: no Shadow IT, higher productivity, and a safe working environment.
Conclusion
Shadow IT is not the problem, but a signal that employees are not sufficiently facilitated. Identity & Access Management makes a difference by combining convenience and security. With HR-driven provisioning, SSO, Entra ID, and AD integration you prevent employees from finding their own ways and create an environment where security and productivity go hand in hand.
👉 Want to learn how Joinly helps organisations reduce Shadow IT and simplify IAM? Contact us to schedule a demo.
Explore more blogs

Segregation of Duties (SoD): wat het is en hoe je het afdwingt
Wat is segregation of duties (functiescheiding)? Uitleg, voorbeelden en waarom het vaak misgaat. Plus hoe je SoD-conflicten automatisch tegenhoudt.
Marcel van Beek · 4 min read

How do you apply AGDLP in a hybrid Entra/AD environment? (And why you shouldn't want to anymore)
Short answer: preferably not. AGDLP (Accounts → Global groups → Domain Local groups → Permissions) is a concept from the era of manual management. The entire nesting construction exists for one reason: to allow a human to assign permissions with as few mouse clicks as possible. As soon as an agent assigns group memberships directly based on HR data, this reason disappears and only the complexity remains. Moreover, in a hybrid environment, this complexity actively works against you, because Entra ID completely ignores nesting for licences and app assignment. In this article, you can read how AGDLP works and why it was once smart, where it breaks down in a hybrid environment, and what the modern alternative looks like: direct memberships, managed by automation.
Marcel van Beek · 5 min read

How do I set up role-based access control (RBAC) and least privilege for a municipality?
Start with the roles in your HR system and map them to roles, not to individual permissions per person. Group each role with precisely the access required for the job, adhering to the principle of least privilege. Manage these roles centrally and let an orchestration layer automatically assign and revoke them. This keeps access predictable, limited and demonstrable.
Mike Fraanje · 4 min read
See what Joinly can do for your organisation?
Start a free trial today or get in touch for advice on your HR and Microsoft environment.