First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Shadow IT Assessment Workshop (Full - 4 consulting days, 3 days on-site)
Training

Shadow IT Assessment Workshop — Cloud App Visibility & Control

The Shadow IT Assessment Workshop is a structured engagement for organizations that want to discover and review usage of cloud applications and services that may be managed or used without the knowledge of the IT department. IT Partner uses Microsoft Defender for Cloud Apps to evaluate cloud application and service usage from within the organization network, then provides findings, recommendations, and a prioritized Cloud Usage Visibility and Control road map.

Timeline 2 weeksService owner Mike MackeyOffice 365microsoft 365

What this engagement is

Shadow IT refers to applications and infrastructure that are managed and utilized without the knowledge of the enterprise's IT department. This workshop helps the customer discover possible Shadow IT by assessing cloud application and service usage with Microsoft Defender for Cloud Apps, managed in the unified Microsoft Defender portal. The engagement covers cloud security objectives and requirements, Microsoft Defender for Cloud Apps readiness and setup, review of discovered usage, and creation of a final report and prioritized road map.

Success criteria

01Good security principals that cover people, process, and technology solutions
02Improve the security posture when it comes to usage of cloud applications and services
03The assessment is based on the discovery of usage of cloud applications and services

What you receive

Kickoff presentation (work product), overview of the engagement covering vision and objectives, requirements and next steps
Pre-assessment questionnaire (work product), a questionnaire containing questions on cloud usage/adoption, security requirements and objectives, regulations and frameworks.
Shadow IT Discovery Report (deliverable), a document containing a list of discovered possible Shadow IT usage and recommendations for their further investigation
Cloud Usage Visibility and Control road map, a prioritized, actionable road map for addressing discovered cloud usage, especially its Shadow IT aspect, including mapping capabilities of Microsoft Defender for Cloud Apps in the customer's environment.

How the work unfolds

Week One -- Kickoff

Up to two-hour remote kickoff meeting. Activities include: introduction to the engagement: objectives, flow, responsibilities, and governance; provide and explain preassessment questionnaire to the customer; make key decisions on resources and tools that will be used in the engagement.

Week Two -- Day 1: Education & Setup

Whole-day on-site workshop. Activities include: review of questionnaire in order to get mutual understanding, especially over customer's cloud usage and associated security objectives and requirements; provide education and readiness on Microsoft Defender for Cloud Apps; technical setup of tools (tenant setup, log upload, Log Collector). Example schedule: On-site Engagement Overview, 60 minutes, all project team, outcome is agreed plan and schedule for the on-site assessment; Review Questionnaire, 60 minutes, all project team, outcome is prioritized list of security requirements; Introduction to Defender for Cloud Apps, 60 minutes, Security Architects, Security Engineers, Network Engineers if applicable, M365 Tenant Admin, outcome is setting the stage and providing a high-level overview of Microsoft Defender for Cloud Apps features; Lunch, 60 minutes; Demonstrate Defender for Cloud Apps visibility and control over cloud usage, 60 minutes, Security Architects, Security Engineers, Network Engineers if applicable, M365 Tenant Admin, outcome is deep dive into selected Microsoft Defender for Cloud Apps features, especially Discovery; Technical Setup with the customer, 180 minutes, Security Engineers, Network Engineers if applicable, M365 Tenant Admin, outcome is logs from customer's firewalls/proxies provided to Defender for Cloud Apps for analysis and Log Collector deployed, if needed.

Week Three or Four -- Day 2: Exploration & Discovery

Whole-day on-site workshop. Activities include: review the Defender for Cloud Apps report(s) with the customer; exploration of specific use cases of cloud usage in the portal; creation of final report from engagement, highlighting discovered cases of Shadow IT (usage of unapproved cloud applications or services); creation of Cloud Usage Visibility and Control road map. Example schedule: Guided exploration with the customer, 180 minutes, Security Architects, Security Engineers, M365 Tenant Admin, outcome is visibility into cloud usage in customer's environment; Lunch, 60 minutes; Create Shadow IT Discovery report, 180 minutes, no customer attendees required except occasional access to M365 Tenant Admin might be necessary, outcome is Discovery report; Create Cloud Usage Visibility and Control road map, 60 minutes, no customer attendees, outcome is Cloud Usage Visibility and Control road map. Actions can include user awareness campaigns/training, blocking/control mechanisms, deployment of discovery/control through Microsoft Defender for Cloud Apps deployment.

Week Three or Four -- Day 3: Review & Road map

Half-day on-site or remotely delivered workshop. Activities include: presentation and discussion of the final report from the engagement, highlighting discovered cases of Shadow IT (usage of unapproved cloud applications or services); review of Cloud Usage Visibility and Control road map. Example schedule: Review of Shadow IT Discovery report, 120 minutes, all project team, outcome is mutual understanding of discovery report; Review of Cloud Usage Visibility and Control road map, 30 minutes, all project team, outcome is mutual understanding of Cloud Usage Visibility and Control road map; Project close-out and next steps, 30 minutes, all project team, outcome is provide an engagement summary and clear steps with tangible outcomes; Lunch, 60 minutes.

Week Three or Four -- Day 3: Project CleanUp

Activities include: removing uploaded logs; decommissioning of Log Collector; closing Microsoft 365 and Defender for Cloud Apps trials, if needed. Example schedule: Project CleanUp, 60 minutes, O365 Tenant Admin, outcome is customer environment left in clean state.

Prerequisites

Microsoft 365 tenant with microsoft Defender for Cloud Apps licensing for in-scope users — included in Microsoft 365 E5 and in the Microsoft 365 E5 Security add-on, or available standalone; a Microsoft trial can be used for evaluation.
Access to logs from customer firewalls or proxies
Infrastructure to host the Log Collector (if applicable), per Microsoft's Defender for Cloud Apps Log Collector documentation

Who does what

IT Partner

  • Gain an understanding of customer's cloud security objectives and requirements towards cloud usage and verify them against real usage of cloud applications and services
  • Provide guidance, recommendations, and best practices on how to successfully use Microsoft Defender for Cloud Apps to mitigate security threats that are associated with usage of cloud application and services
  • Provide a prioritized and actionable road map for the customer containing proposed actions based on user impact and implementation cost
  • Map Microsoft Defender for Cloud Apps capabilities and partner services to assessment findings, taking into account customer's security objectives and requirements

Your team

  • Information: This includes accurate, timely (within three business days or as mutually agreed upon), and complete information
  • Access to people: This includes access to knowledgeable customer personnel, including business user representatives, and access to funding if additional budget is needed to deliver project scope Access to knowledgeable personnel who manage the firewalls, can provide credentials for log extraction, and can alter firewall rules if necessary
  • Access to systems: This includes access to all necessary customer work locations, networks, systems, and applications (remote and on-site)
  • A work environment: This consists of suitable work spaces, including desks, chairs, and Internet access.

What's not included

Implementation of remediation actions identified in the Cloud Usage Visibility and Control road map, including blocking applications, creating production enforcement policies, or changing user access controls, unless separately scoped.
Full production deployment, long-term operation, or managed monitoring of Microsoft Defender for Cloud Apps beyond the assessment setup and discovery activities described in this engagement.
Purchase of Microsoft 365, Microsoft Defender for Cloud Apps, Microsoft 365 E5, third-party firewall, proxy, SIEM, or other software licenses or subscriptions, unless separately stated in the applicable agreement.
Firewall, proxy, network, endpoint, identity, or application configuration changes outside the log extraction, log upload, or Log Collector setup support required for the assessment.
Custom integrations, custom report development, custom automation, API development, or integration with third-party governance, risk, compliance, ticketing, SIEM, or SOAR platforms.
Formal legal, regulatory, audit, or compliance certification services. Findings and recommendations are advisory and should be validated by the customer's compliance, legal, and risk teams where required.
End-user communications, user awareness campaigns, training rollout, change management execution, or business process redesign recommended by the road map unless separately scoped.
Investigation or remediation of security incidents, malware, data loss events, insider risk events, or compromised accounts discovered during the assessment; these should be handled under a separate incident response or security remediation engagement.
Cleanup, normalization, enrichment, or recovery of missing, incomplete, corrupted, or unavailable firewall/proxy logs beyond reasonable assessment troubleshooting.
Travel, expenses, after-hours work, or additional on-site days beyond the agreed workshop scope, unless included in the applicable statement of work or commercial agreement.

Limitations & technical notes

!The Shadow IT Assessment typically consists of an up to two-hour remote kickoff meeting, followed by on-site assessment workshops split into three days (Day 1, 2, and 3) over up to four consecutive weeks, preceded by preparations and followed by clean-up activities.
!Between Kickoff and Day 1, at least one (1) week is needed for the customer to prepare and fill in the questionnaire, as well as time for IT Partner to prepare some engagement tools (trial Microsoft 365 tenant and trial Defender for Cloud Apps).
!Between Day 1 and Day 2, at least 2 -- 3 days are needed if using the manual method of uploading logs to Defender for Cloud Apps; this time is needed for Defender for Cloud Apps to parse and analyze logs.
!Between Day 1 and Day 2, at least two (2) (ideally three) weeks are needed if logs are uploaded to Defender for Cloud Apps automatically via the Log Collector; this time is needed to collect, parse, and analyze a reasonable amount of logs.
!Between Day 2 and Day 3, these days can potentially be adjacent, but for more sophisticated customers, it is advisable to insert a day or two to allow the partner delivery resource to work on preparation of engagement deliverables.

Frequently asked questions

What is the Shadow IT Assessment Workshop?

The Shadow IT Assessment Workshop is a structured IT Partner engagement that helps organizations discover and review cloud applications and services used without IT’s knowledge. IT Partner uses Microsoft Defender for Cloud Apps to evaluate cloud usage from the organization’s network and then provides findings, recommendations, and a prioritized Cloud Usage Visibility and Control road map.

Who is this Shadow IT Assessment Workshop designed for?

This workshop is designed for organizations that want better visibility into cloud applications and services being used by employees, especially services that may not be approved or managed by IT. It is most relevant when the organization wants to improve cloud security posture using Microsoft Defender for Cloud Apps and align people, process, and technology controls around cloud usage.

What deliverables does IT Partner provide at the end of the workshop?

IT Partner provides a kickoff presentation, a pre-assessment questionnaire, a Shadow IT Discovery Report, and a Cloud Usage Visibility and Control road map. The discovery report lists possible Shadow IT usage and recommendations for further investigation, while the road map prioritizes actions for improving visibility and control of cloud usage in the customer environment.

How long does the Shadow IT Assessment Workshop take?

In practice, the assessment typically includes an up to two-hour remote kickoff followed by on-site workshops over Day 1, Day 2, and Day 3, and the full schedule may extend up to four consecutive weeks depending on log collection and analysis timing.

What are the prerequisites for the Shadow IT Assessment Workshop?

The customer needs a Microsoft 365 tenant with microsoft Defender for Cloud Apps licensing for in-scope users — included in Microsoft 365 E5 and in the Microsoft 365 E5 Security add-on, or available standalone; a Microsoft trial can be used for evaluation. The customer also needs access to firewall or proxy logs and, if the Log Collector is used, infrastructure to host it.

Do we need Microsoft 365 E5 for this assessment?

Not necessarily. Microsoft Defender for Cloud Apps licensing for in-scope users — included in Microsoft 365 E5 and in the Microsoft 365 E5 Security add-on, or available standalone; a Microsoft trial can be used for evaluation. A trial Microsoft 365 tenant with a Defender for Cloud Apps trial can also be used for the assessment when no production licensing is in place.

What log data is required for the assessment?

The assessment requires access to logs from the customer’s firewalls or proxies because Microsoft Defender for Cloud Apps uses those logs to analyze cloud application and service usage. If the Log Collector is used, the customer also needs infrastructure to host it and knowledgeable personnel who can provide credentials, assist with log extraction, and alter firewall rules if necessary.

How much time is needed between workshop sessions for log analysis?

At least one week is needed between kickoff and Day 1 so the customer can complete the questionnaire and IT Partner can prepare engagement tools. Between Day 1 and Day 2, at least 2 to 3 days are needed for manual log uploads, while Log Collector-based collection typically needs at least two weeks, ideally three, to collect and analyze a reasonable amount of data.

Will the workshop cause downtime or disrupt users?

The service is an assessment and discovery engagement, so it is not described as requiring production downtime or user cutovers. Business impact is primarily the time required from security, network, and Microsoft 365 administrators, plus access to firewall or proxy logs and any required Log Collector setup.

Does IT Partner block or remove Shadow IT applications during this engagement?

The stated scope is assessment, discovery, reporting, and road map creation, not a full remediation or enforcement rollout. The road map may recommend actions such as user awareness campaigns, blocking or control mechanisms, or broader Microsoft Defender for Cloud Apps deployment, but implementation of those actions should be confirmed separately with IT Partner.

How much does the Shadow IT Assessment Workshop cost?

The workshop is $4,500 per project. Travel assumptions, licensing, and any follow-on implementation work are confirmed with IT Partner before the engagement so the commercial terms are clear up front.

What happens after the Shadow IT Assessment Workshop is completed?

After completion, the customer has a Shadow IT Discovery Report and a prioritized Cloud Usage Visibility and Control road map to guide next steps. The close-out also includes cleanup activities such as removing uploaded logs, decommissioning the Log Collector, and closing Microsoft 365 or Defender for Cloud Apps trials if they were used.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$4,500 per project
2 weeks
Book a meeting