Unauthorized Applications Detection
Highlights applications with low or no usage so IT can reclaim licenses, reduce SaaS spend, and shrink the application attack surface
- Runs on a configurable schedule across all IdP-connected applications
- Identifies apps that aren't formally approved and have been active beyond the threshold
- Compiles a report with ownership, usage history, and adoption details
- Opens a ticket and attaches the report for admin review
- Notifies the right IT stakeholders through their preferred communi-cation channel
What Unauthorized Applications Detection does
Unauthorized Applications Detection is Harmony's automated monitoring workflow for surfacing applications that are active in the identity provider but have never been formally reviewed or approved. Running on a weekly schedule, Harmony queries all IdP-sourced applications, identifies those without an approved status, generates a CSV report with owner, user count, and first/last seen dates, and creates an IT desk ticket with the findings. IT admins can then approve, reject, or remove each application to keep the catalog governed and under control.
Who Unauthorized Applications Detection Is For
IT admins and security teams responsible for application governance and shadow IT management.
New applications constantly appear in identity providers - added by users, vendors, or automated SSO connections - and many are never formally reviewed. Without monitoring, unapproved applications accumulate silently, creating security risks (unknown data access), compliance exposure (ungoverned app permissions), and license waste. This workflow creates a standing weekly audit of what's in the IdP vs. what's been approved.
How Unauthorized Applications Detection Works
A cron schedule fires (default: weekly, Monday at 8 AM UTC). Schedule and timezone are configurable per tenant.
- Query unauthorized applications
The workflow queries all applications sourced from the configured IdPs (Okta, Microsoft Entra, Google Workspace, JumpCloud) that have not been formally approved in Harmony's application catalog.
- CSV report
All unauthorized apps are serialized into a structured CSV with: Application Name, Display Name, Status, Owner, Category, Vendor, Source, Last Seen, First Seen, Total Users, Total Instances.
- Ticket creation
A ticket titled "Application Health Check: Unauthorized Applications" is created with the CSV attached and the app IDs embedded in ticket metadata so IT can act on each directly.
The ticket assignee or desk managers are notified via Slack or Teams.
Capabilities
- Cross-IdP unauthorized app detection - Queries Okta, Microsoft Entra, Google Workspace, and JumpCloud simultaneously for any application not formally approved in the catalog.
- Rich metadata in CSV - Each unauthorized app row includes owner, category, vendor, source IdP, first-seen date, last-seen date, total user count, and total instance count - giving IT full context to make approval decisions.
- App IDs in ticket metadata - The ticket metadata includes the actual application IDs so IT can navigate directly to each app in the catalog from the ticket.
- Configurable IdP source list - The list of IdPs to scan is configurable per tenant; unused IdPs can be excluded.
- Notification routing - Notifies the configured assignee; falls back to desk managers if no assignee is set.
- Configurable schedule - Cron schedule and timezone are fully configurable per tenant.
Main use cases
Weekly Shadow IT Audit - IT wants a standing weekly view of all applications added to Okta that haven't gone through the formal app review process. Every Monday morning, the workflow surfaces any newly added or previously overlooked apps without an approved status, with full owner and usage data. IT reviews the CSV, approves the legitimate ones, and rejects or removes the unauthorized ones.
Post-Merger Application Review - An acquired company's Okta tenant was merged and hundreds of applications need to be reviewed for approval status. The first run surfaces all unapproved apps with their user counts and first-seen dates - giving IT a prioritized, data-rich list to work through systematically.
Compliance Evidence for App Governance - A security audit requires evidence that the organization has a process for detecting and reviewing unapproved applications. The workflow provides recurring, timestamped tickets showing that unauthorized apps are detected, reviewed, and actioned - creating an audit trail for the governance process.
Integrations
| Integration | Role in the agent flow |
|---|---|
| Okta | Queried for IdP-sourced applications without approved catalog status (configured per tenant) |
| Microsoft Entra | Queried for IdP-sourced applications without approved catalog status (configured per tenant) |
| Google Workspace | Queried for IdP-sourced applications without approved catalog status (configured per tenant) |
| JumpCloud | Queried for IdP-sourced applications without approved catalog status (configured per tenant) |
| Application Catalog (internal) | Reference data - the approval status of each app is checked against the catalog to determine what counts as "unauthorized" |
| Service Desk (internal) | Ticket created with CSV and app IDs in metadata; tracked by IT for review and action |
| Notifications system (Slack/Teams) | Notifies assignee or desk managers when unauthorized apps are detected |
FAQ
Any application that is actively sourced from a connected IdP but does not have a formally approved status in Harmony's application catalog. An application added to Okta through SSO configuration but never reviewed in the catalog counts as unauthorized.
Meet more Agents