Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes Hey HN, TL;DR: We’ve launched a free version of our Shadow IT scanner to identify which SaaS apps are used in your company, who uses them, and if they have high-risk OAuth scopes. Philip and I went through YC with AccessOwl in 2022. We started the company because, in our previous roles, we struggled to track all the SaaS apps, users, and granted OAuth scopes. The Shadow IT scanner started as a small feature within AccessOwl, which manages SaaS vendors and user accounts centrally. But a standalone scanner would have made our lives so much easier in our previous roles. So, we thought, why not release it? And here it is: a free, standalone Shadow IT scanner! Hope you find it useful :) The Shadow IT scan helps with: 1. Offboarding: Employees often don’t report all the apps they sign up for, making it tough to track and secure these accounts when they leave, especially with the common SSO tax. 2. Security: OAuth scopes are quickly granted but rarely reviewed or removed, leading to organizations unknowingly spreading their data. 3. Compliance: Auditors need a list of SaaS vendors, which is hard to compile when employees sign up for tools independently. Any surprises in your scan? What features would you like to see in the next version? Looking forward to your feedback! FAQ What’s Shadow IT? Unauthorized SaaS apps within an organization not centrally managed, posing security and compliance risks. How does it work? Our tool connects to your Google Workspace or M365 instance, identifies OAuth tokens granted, and maps them to known SaaS tools. Note: In this v1 version, it only detects apps using the “Sign in with Google/Microsoft” button. Who is this for? Typically IT and InfoSec teams, but in smaller companies, it may fall under the CTO. Is it safe to use? Yes, reading OAuth tokens is standard for SaaS management tools. Data extraction only occurs when you initiate a scan. AccessOwl is SOC 2 Type II audited and GDPR compliant. https://ift.tt/LNrUydE July 31, 2024 at 05:35PM
Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes https://ift.tt/cWpoD6z
Related Articles
Show HN: Open multiple tabs with a single URL https://ift.tt/3iiZPNYShow HN: Open multiple tabs with a single URL https://polyl.ink/ Janua… Read More
Show HN: Il2cpp-modder – Generate DLL injection projects for hacking Unity games https://ift.tt/39NLqpdShow HN: Il2cpp-modder – Generate DLL injection projects for hacking U… Read More
Show HN: I made a free iOS 14 home screen icon generator https://ift.tt/38mTqOkShow HN: I made a free iOS 14 home screen icon generator https://ift.t… Read More
Show HN: I built a Twitter client tailored to my workflows https://ift.tt/3pcTh6dShow HN: I built a Twitter client tailored to my workflows https://ift… Read More
Show HN: RemoteClub – Best cities to work remotely across the world https://ift.tt/35Px4U7Show HN: RemoteClub – Best cities to work remotely across the world ht… Read More
Show HN: Amazon for Entrepreneurship / LinkedIn for Startups https://ift.tt/3p6Q6wXShow HN: Amazon for Entrepreneurship / LinkedIn for Startups https://i… Read More
Show HN: An Interactive GPU/CPU Path Tracer on DXR/Vulkan/Metal/OptiX/Embree https://ift.tt/3bRhZVUShow HN: An Interactive GPU/CPU Path Tracer on DXR/Vulkan/Metal/OptiX/… Read More
Show HN: Extension.dev – quickly build custom internal Chrome extensions https://ift.tt/398ljZEShow HN: Extension.dev – quickly build custom internal Chrome extensio… Read More
0 Comments: