If you want to find the cloud apps nobody approved, don't start with a policy. Start with your browser history.
The cloud setup most businesses actually run rarely matches the tidy diagram. It's built from countless small shortcuts: a "just this once" file share, a free tool that solved one problem faster, an add-on installed to hit a deadline, an AI feature quietly switched on inside something you already pay for. None of it feels like a problem in the moment, until your business data is scattered across tools you never vetted, accounts you can't easily shut off, and sharing settings that don't match the real risk.
Why this is a bigger deal in 2026
Unapproved apps have always existed. What's changed is the scale and the speed. Microsoft's own research found that while IT teams tend to assume staff use 30 or 40 cloud apps, the real average is over a thousand, and roughly 80% of employees use apps that were never checked against company policy. The gap between what you think is happening and what's actually happening is usually much wider than expected.
Add the new twist: AI features now hide inside everyday apps, so you can pick up risk without anyone signing up for a new product. Industry researchers report that most employees would use AI tools even without approval, and that breaches tied to unapproved AI use have added hundreds of thousands of dollars to clean-up costs. This isn't only a tidiness problem. It's a measurable risk.
Don't start by blocking
The fastest way to push app use further underground is to treat it as a discipline problem and reach straight for bans. Some apps genuinely do need blocking, but if that's your first move, two things tend to happen: people get better at hiding what they're doing, or they switch to a different tool that's just as risky. Either way you haven't shrunk the problem, you've just made it harder to see.
A better start is to understand what's happening and why, then respond in a way that lasts: approve some apps, put limits on others, replace a few, and block the genuinely high-risk ones thoughtfully, with a clear message and a secure alternative so people can still do their jobs.
A workflow you can actually repeat
This isn't a one-time cleanup. It's something you run each quarter to stay ahead of new tools and new habits.
Discover what's in use
Build a real inventory from signals you already collect: activity on your computers, sign-in logs, network data, and browser activity. You can't manage what you haven't first identified.
Look at how it's being used
Don't stop at the list of apps. Check who's using them, what's being shared publicly or to personal accounts, and whether access exists that shouldn't, like a former employee whose connection is still live.
Score and prioritize the risk
Not every unapproved app is equally dangerous. Weigh a few simple things: how sensitive the data is, how it's being shared, how strong the sign-in controls are, how much visibility you have, and whether AI features could be soaking up or exposing data.
Tag each app, then act
Mark each app as approved or not so decisions are visible and repeatable. Then enforce them. Often that's as light as a friendly warning nudging better behavior, and sometimes it's blocking access outright. Plan the communication and a smooth handover rather than flipping a switch and causing surprise disruption.
Your new default: discover, decide, enforce
Unapproved cloud apps aren't going away in 2026. If anything they'll keep multiplying as more AI features appear inside the tools you already use. The goal isn't to block everything. It's a repeatable rhythm: discover what's in use, decide what's acceptable, and enforce it with clear guidance and secure alternatives. The same discipline applies to the AI tools specifically; see finding the AI tools your team is using.
If you'd like help building a practical way to keep cloud sprawl in check without slowing people down, that's the kind of thing we set up and keep an eye on for our clients.