Find Shadow IT and Shadow AI with Cloud App Discovery
June 5, 2026 · InfraScout Team
Every organization runs more cloud apps than its IT team has approved. Someone signs up for a file-sharing service, a team adopts a project tool, an engineer pipes data to an AI model provider — and none of it shows up in a sanctioned-apps list. That gap is shadow IT, and it is where unmanaged data flows and unvetted vendors hide. With this update, InfraScout reads Microsoft Defender for Cloud Apps Cloud Discovery data directly inside an assessment conversation, so you can see which cloud apps are actually in use across your organization, how risky each one is, and who is using it — without leaving the chat.
See the apps your org is actually using
Cloud Discovery builds its picture from the network traffic Microsoft Defender for Cloud Apps observes, whether that comes from uploaded discovery logs or from devices reporting through Microsoft Defender for Endpoint. InfraScout surfaces that picture as a set of read-only tools the AI can call mid-investigation.
You can start broad: ask for the discovered apps across the organization and InfraScout returns each app with its risk score, observed traffic, category, and tags. From there you can narrow the view — filter by risk threshold to focus on the riskiest apps first, by category to look at a class of service, or by tag and domain to find specific vendors. When a filter can't be expressed cleanly, InfraScout falls back to scanning the discovered apps and tells you plainly how far it got, so an incomplete sweep is never mistaken for a clean bill of health.
Because the data spans an organization's worth of traffic, results come back a page at a time. InfraScout applies a sensible default page size and hands back a clear pointer to the next page, so a question like "show me the next batch of risky apps" just works.
Drill into a single app's risk and compliance profile
Spotting a risky app is only the first step; the next question is always "how risky, exactly, and why?" Open any discovered app and InfraScout returns its full profile — a rich block of risk and compliance attributes covering things like the vendor's data-handling posture, certifications, hosting, and security controls. Attributes that Microsoft has no data for are dropped from the response rather than shown as empty noise, so what you get back is the signal: the concrete factors that drive the app's risk score.
That turns a vague "this app looks risky" into an evidence-backed finding you can record. If a tool surfaces a high-risk file-sharing app with no meaningful compliance posture, you can save that as an insight on the spot, with the specific attributes that justify it.
Connect apps to the people and devices using them
Risk in the abstract is hard to act on. The value comes from knowing who is reaching a given app. For any discovered app, InfraScout can list the users, devices, and source IP addresses associated with it — the identifiers you need to scope an investigation or a conversation with a team.
It also works the other way around. Point InfraScout at a single user or device and ask what cloud apps they are using, and it builds a reverse view across the discovered data. That is the question that comes up when a device looks compromised or a user's behavior raises a flag: "what is this entity actually talking to?" — answered in one step.
App-level traffic only
Worth knowing up front: the underlying Cloud Discovery data reports traffic at the app level. You can see which users and devices touched an app, but there is no per-user or per-device traffic breakdown anywhere in this data — that granularity simply isn't available from the source. InfraScout surfaces the entity-to-app relationships it has and is explicit about this boundary rather than implying a precision the data doesn't carry.
Shadow AI, as it emerges
The fastest-growing slice of shadow IT right now is AI. Staff reach for AI model providers, connect tooling to MCP servers, and adopt AI client apps faster than any approval process can keep up. Cloud Discovery categorizes these as they appear, and InfraScout is built to surface those emerging categories rather than silently dropping anything it doesn't already recognize. As new AI-related app categories show up in your discovered traffic, they come through in the results — so the same workflow that finds an unsanctioned file-sharing tool also surfaces the AI services your organization has quietly started depending on.
That makes "is anyone sending data to an outside AI service, and which ones?" a question you can answer today, against your real traffic, instead of a governance project for next quarter.
One-time admin step
Cloud Discovery reads from Microsoft Defender for Cloud Apps, so an administrator grants one application permission to the Entra app registration behind each connection: CloudApp-Discovery.Read.All, with admin consent. Once that consent is in place, the discovery tools are available to every assessment using that connection. As with the rest of InfraScout's cloud tools, this is read-only and agentless — there is nothing to install on any device, and nothing in your tenant changes.
Try it
Open an assessment and start with the big picture — "what are the riskiest cloud apps discovered across the org?" Drill into one that stands out and ask why it scores the way it does. Then pivot to people: "who is using this app?" or, from the other direction, "what cloud apps is this device reaching?" InfraScout picks the right tool, reads from your tenant, and returns results you can turn into insights without leaving the conversation.
Questions or feedback? Reach us at info@infrascout.cloud.