Skip to content

Shadow-app scan

The shadow scan reveals the third-party applications that have access to your organization's data on Google Workspace or Microsoft — including those nobody declared (shadow IT).

How it works

You start a scan by authorizing MIA in read-only mode on your directory (Google or Microsoft). MIA then lists the connected third-party applications and, for each one:

  • the users involved,
  • the permissions (scopes) granted,
  • the consent type (granted by a user or by an administrator),
  • a category (for Microsoft).

Importing detected applications

From the results, select the applications to import into your inventory: MIA creates manual applications for them. You move from unmanaged shadow IT to a controlled inventory.

Purely technical applications, or those with no access trace, aren't importable; disabled accounts are never imported.

Good to know

  • The scan is free, and can even be run without an account thanks to a public, open-access version.
  • Imported applications are manual: they don't count toward the free-plan limit.
  • Application categories are only available for Microsoft.
  • A full scan requires an administrator account of the workspace.