Shadow IT Assessment Workshop — Cloud App Visibility & Control
The Shadow IT Assessment Workshop is a structured engagement for organizations that want to discover and review usage of cloud applications and services that may be managed or used without the knowledge of the IT department. IT Partner uses Microsoft Defender for Cloud Apps to evaluate cloud application and service usage from within the organization network, then provides findings, recommendations, and a prioritized Cloud Usage Visibility and Control road map.
What this engagement is
Shadow IT refers to applications and infrastructure that are managed and utilized without the knowledge of the enterprise's IT department. This workshop helps the customer discover possible Shadow IT by assessing cloud application and service usage with Microsoft Defender for Cloud Apps, managed in the unified Microsoft Defender portal. The engagement covers cloud security objectives and requirements, Microsoft Defender for Cloud Apps readiness and setup, review of discovered usage, and creation of a final report and prioritized road map.
Success criteria
What you receive
How the work unfolds
Up to two-hour remote kickoff meeting. Activities include: introduction to the engagement: objectives, flow, responsibilities, and governance; provide and explain preassessment questionnaire to the customer; make key decisions on resources and tools that will be used in the engagement.
Whole-day on-site workshop. Activities include: review of questionnaire in order to get mutual understanding, especially over customer's cloud usage and associated security objectives and requirements; provide education and readiness on Microsoft Defender for Cloud Apps; technical setup of tools (tenant setup, log upload, Log Collector). Example schedule: On-site Engagement Overview, 60 minutes, all project team, outcome is agreed plan and schedule for the on-site assessment; Review Questionnaire, 60 minutes, all project team, outcome is prioritized list of security requirements; Introduction to Defender for Cloud Apps, 60 minutes, Security Architects, Security Engineers, Network Engineers if applicable, M365 Tenant Admin, outcome is setting the stage and providing a high-level overview of Microsoft Defender for Cloud Apps features; Lunch, 60 minutes; Demonstrate Defender for Cloud Apps visibility and control over cloud usage, 60 minutes, Security Architects, Security Engineers, Network Engineers if applicable, M365 Tenant Admin, outcome is deep dive into selected Microsoft Defender for Cloud Apps features, especially Discovery; Technical Setup with the customer, 180 minutes, Security Engineers, Network Engineers if applicable, M365 Tenant Admin, outcome is logs from customer's firewalls/proxies provided to Defender for Cloud Apps for analysis and Log Collector deployed, if needed.
Whole-day on-site workshop. Activities include: review the Defender for Cloud Apps report(s) with the customer; exploration of specific use cases of cloud usage in the portal; creation of final report from engagement, highlighting discovered cases of Shadow IT (usage of unapproved cloud applications or services); creation of Cloud Usage Visibility and Control road map. Example schedule: Guided exploration with the customer, 180 minutes, Security Architects, Security Engineers, M365 Tenant Admin, outcome is visibility into cloud usage in customer's environment; Lunch, 60 minutes; Create Shadow IT Discovery report, 180 minutes, no customer attendees required except occasional access to M365 Tenant Admin might be necessary, outcome is Discovery report; Create Cloud Usage Visibility and Control road map, 60 minutes, no customer attendees, outcome is Cloud Usage Visibility and Control road map. Actions can include user awareness campaigns/training, blocking/control mechanisms, deployment of discovery/control through Microsoft Defender for Cloud Apps deployment.
Half-day on-site or remotely delivered workshop. Activities include: presentation and discussion of the final report from the engagement, highlighting discovered cases of Shadow IT (usage of unapproved cloud applications or services); review of Cloud Usage Visibility and Control road map. Example schedule: Review of Shadow IT Discovery report, 120 minutes, all project team, outcome is mutual understanding of discovery report; Review of Cloud Usage Visibility and Control road map, 30 minutes, all project team, outcome is mutual understanding of Cloud Usage Visibility and Control road map; Project close-out and next steps, 30 minutes, all project team, outcome is provide an engagement summary and clear steps with tangible outcomes; Lunch, 60 minutes.
Activities include: removing uploaded logs; decommissioning of Log Collector; closing Microsoft 365 and Defender for Cloud Apps trials, if needed. Example schedule: Project CleanUp, 60 minutes, O365 Tenant Admin, outcome is customer environment left in clean state.
Prerequisites
Who does what
IT Partner
- Gain an understanding of customer's cloud security objectives and requirements towards cloud usage and verify them against real usage of cloud applications and services
- Provide guidance, recommendations, and best practices on how to successfully use Microsoft Defender for Cloud Apps to mitigate security threats that are associated with usage of cloud application and services
- Provide a prioritized and actionable road map for the customer containing proposed actions based on user impact and implementation cost
- Map Microsoft Defender for Cloud Apps capabilities and partner services to assessment findings, taking into account customer's security objectives and requirements
Your team
- Information: This includes accurate, timely (within three business days or as mutually agreed upon), and complete information
- Access to people: This includes access to knowledgeable customer personnel, including business user representatives, and access to funding if additional budget is needed to deliver project scope Access to knowledgeable personnel who manage the firewalls, can provide credentials for log extraction, and can alter firewall rules if necessary
- Access to systems: This includes access to all necessary customer work locations, networks, systems, and applications (remote and on-site)
- A work environment: This consists of suitable work spaces, including desks, chairs, and Internet access.
What's not included
Limitations & technical notes
Frequently asked questions
What is the Shadow IT Assessment Workshop?
The Shadow IT Assessment Workshop is a structured IT Partner engagement that helps organizations discover and review cloud applications and services used without IT’s knowledge. IT Partner uses Microsoft Defender for Cloud Apps to evaluate cloud usage from the organization’s network and then provides findings, recommendations, and a prioritized Cloud Usage Visibility and Control road map.
Who is this Shadow IT Assessment Workshop designed for?
This workshop is designed for organizations that want better visibility into cloud applications and services being used by employees, especially services that may not be approved or managed by IT. It is most relevant when the organization wants to improve cloud security posture using Microsoft Defender for Cloud Apps and align people, process, and technology controls around cloud usage.
What deliverables does IT Partner provide at the end of the workshop?
IT Partner provides a kickoff presentation, a pre-assessment questionnaire, a Shadow IT Discovery Report, and a Cloud Usage Visibility and Control road map. The discovery report lists possible Shadow IT usage and recommendations for further investigation, while the road map prioritizes actions for improving visibility and control of cloud usage in the customer environment.
How long does the Shadow IT Assessment Workshop take?
In practice, the assessment typically includes an up to two-hour remote kickoff followed by on-site workshops over Day 1, Day 2, and Day 3, and the full schedule may extend up to four consecutive weeks depending on log collection and analysis timing.
What are the prerequisites for the Shadow IT Assessment Workshop?
The customer needs a Microsoft 365 tenant with microsoft Defender for Cloud Apps licensing for in-scope users — included in Microsoft 365 E5 and in the Microsoft 365 E5 Security add-on, or available standalone; a Microsoft trial can be used for evaluation. The customer also needs access to firewall or proxy logs and, if the Log Collector is used, infrastructure to host it.
Do we need Microsoft 365 E5 for this assessment?
Not necessarily. Microsoft Defender for Cloud Apps licensing for in-scope users — included in Microsoft 365 E5 and in the Microsoft 365 E5 Security add-on, or available standalone; a Microsoft trial can be used for evaluation. A trial Microsoft 365 tenant with a Defender for Cloud Apps trial can also be used for the assessment when no production licensing is in place.
What log data is required for the assessment?
The assessment requires access to logs from the customer’s firewalls or proxies because Microsoft Defender for Cloud Apps uses those logs to analyze cloud application and service usage. If the Log Collector is used, the customer also needs infrastructure to host it and knowledgeable personnel who can provide credentials, assist with log extraction, and alter firewall rules if necessary.
How much time is needed between workshop sessions for log analysis?
At least one week is needed between kickoff and Day 1 so the customer can complete the questionnaire and IT Partner can prepare engagement tools. Between Day 1 and Day 2, at least 2 to 3 days are needed for manual log uploads, while Log Collector-based collection typically needs at least two weeks, ideally three, to collect and analyze a reasonable amount of data.
Will the workshop cause downtime or disrupt users?
The service is an assessment and discovery engagement, so it is not described as requiring production downtime or user cutovers. Business impact is primarily the time required from security, network, and Microsoft 365 administrators, plus access to firewall or proxy logs and any required Log Collector setup.
Does IT Partner block or remove Shadow IT applications during this engagement?
The stated scope is assessment, discovery, reporting, and road map creation, not a full remediation or enforcement rollout. The road map may recommend actions such as user awareness campaigns, blocking or control mechanisms, or broader Microsoft Defender for Cloud Apps deployment, but implementation of those actions should be confirmed separately with IT Partner.
How much does the Shadow IT Assessment Workshop cost?
The workshop is $4,500 per project. Travel assumptions, licensing, and any follow-on implementation work are confirmed with IT Partner before the engagement so the commercial terms are clear up front.
What happens after the Shadow IT Assessment Workshop is completed?
After completion, the customer has a Shadow IT Discovery Report and a prioritized Cloud Usage Visibility and Control road map to guide next steps. The close-out also includes cleanup activities such as removing uploaded logs, decommissioning the Log Collector, and closing Microsoft 365 or Defender for Cloud Apps trials if they were used.