How to stop employees buying unapproved SaaS and AI apps
Employees and management ignore official policies to secretly buy unauthorized SaaS and AI tools, sometimes using personal credit cards. When the promised integrations fail, leadership expects IT to fix the mess. IT cannot easily discover these accounts because standard cloud defense tools and tracking agents fail to match firewall logs.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1Turning off user consent for third-party apps in identity providers like Entra ID
- 2Checking the "Connected applications and devices" section of Google Workspace
- 3Blocking access to non-supported application domains via DNS or firewalls
- 4Talking to users to find out why existing tools aren't working for them before shutting the new app down
- 5Relying on HR or Finance to enforce fair-use agreements on company credit cards to stop unauthorized billing
- 6Manually checking firewall logs
- 7Relying on hearsay and manual investigation
- 8Scraping browser history via scripts
In their words
Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.
“The issue I'm becoming more concerned about is users signing up for a service (let's say Airtable for an example) and not letting me know.”source ↗
“We had an unauthorized SaaS event, someone bought a subscription to an AI tool (used his own creditcard because he very well knew I wouldn't allow it).”source ↗
“Plenty of products do what I want and that is to track and log who is logging into a SaaS platform. BUT you'd need to have the AGENTS running.”source ↗
“I couldn't find a lot of info on SCCM agents and what they actually log and if it is useful for SaaS discovery”source ↗
“I currently have four people insistent on using Monday when I've just finished multiple months work to get the company running on Jira.”source ↗
“yeah a lot of our issues with this are management deciding that policies they signed off on don't include whatever bullshit app they've been scammed into trying.”source ↗
“It definitely is already an issue, but it's becoming a bigger one with people signing up for all sorts of AI garbage now too.”source ↗
“I don't even know how to handle management doing this and then trying to make it my problem when the promised "quick and painless integration" isn't either.”source ↗
“We have Defender for Cloud Apps and my admin said he couldn't find any report that matched the firewall logging. That made me sceptical of Defender.”source ↗
Where this came up
People with this problem also raised
- 11How do I dispute a bunch of incorrect charges at once?
- 3Why do CRM apps share my customer data with other companies?
- 3Why can't accountants open Apple Numbers files?
- 2Manager changing my timesheet to add unpaid lunch breaks
- 2Should you charge clients when you switch their software tools?
- 3Unauthorized third-party software integrations on client networks