LastPass just launched a tool to help security teams keep tabs on shadow IT risks
Companies need to know what apps their employees are using, so LastPass made a browser extension to help


LastPass has launched a new feature to help enterprises tackle ‘SaaS sprawl’ and shadow IT security risks.
Unveiled at Black Hat 2025, the new SaaS Protect feature will allow IT admins to see how user-installed apps are being used across their organization — and to take action to avoid misuse or risk.
The new feature follows the launch of its SaaS Monitoring tools in May this year, and aims to provide a consolidated view of app usage and credentials. Both tools are part of LastPass' Secure Access Experience approach.
"Small and mid-sized businesses are facing a perfect storm of complexity: unknown risks living within unknown apps and AI services," said Don MacLennan, Chief Product Officer at LastPass.
"We built SaaS Protect to turn that chaos into clarity," he added.
Shadow IT, whereby employees use applications or devices unknown to IT departments, is on the rise.
This brings with it a range of security-related risks, research shows, largely due to the fact security teams lack visibility into how applications are being used and opening enterprises up to an array of threats.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
LastPass pointed to Gartner statistics that show three-quarters of employees are expected to use unauthorised tech by 2027. Similar research from Zylo shows small and medium businesses have an average of 275 known SaaS applications – but just a quarter of these are authorized by IT teams.
The rest, the study noted, are installed by individual employees or business units, with the latter creating dangerous interdepartmental silos.
Last year, 73% of people polled by Next DLP admitted to using SaaS apps that weren't approved by corporate IT, despite being fully aware of the risk of data breaches.
This long-running issue is now being exacerbated by shadow AI, with unapproved AI bots being used by a third of staff, according to one survey, putting data at risk.
LastPass wants to keep it light
Rather than a device agent that disrupts staff, SaaS Protect is deployed via a browser extension on employee devices, the company revealed. It works by pulling in activity data to an admin console to support policy enforcement, such as allowing or restricting an app or showing a custom warning to guide user behavior.
"It’s designed specifically for resource-constrained businesses that need visibility, policy enforcement, and credential protection without adding operational overhead," said MacLennan.
Alongside spotting and restricting shadow IT, SaaS Protect can also help reduce costs by identifying duplicate or over-licensed apps to help slash app sprawl, as well as assist with creating audits for compliance, the company said.
SaaS Protect is currently in beta for LastPass Business and Business Max customers, the latter of which will pay no additional cost for the product. General availability is expected in early autumn.
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO
- The NCSC wants you to start using password managers and passkeys
- Are password managers safe?
- Looking for a new password manager? Here are our top picks
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
Microsoft patched a critical vulnerability in its NLWeb AI search tool – but there's no CVE (yet)
News Researchers found an unauthenticated path traversal bug in the tool debuted at Microsoft Build in May
-
Three things we expect to see at OpenAI’s GPT-5 reveal event
Analysis Improved code generation and streamlined model offerings are core concerns for OpenAI
-
The NCSC wants you to start using password managers and passkeys – here’s how to choose the best options
News New guidance from the NCSC recommends using passkeys and password managers – but how can you choose the best option? ITPro has you covered.
-
I love magic links – why aren’t more services using them?
Opinion Using magic links instead of passwords is safe and easy but they’re still infuriatingly underused by businesses
-
Password management startup Passbolt secures $8 million to shake up credential security
News Password management startup Passbolt has secured $8 million in funding as part of a Series A investment round.
-
LastPass breach comes back to haunt users as hackers steal $12 million in cryptocurrency
News The hackers behind the LastPass breach are on a rampage two years after their initial attack
-
GitHub launches passkeys beta for passwordless authentication
News Users can now opt-in to using passkeys, replacing their password and 2FA method
-
Microsoft SQL password-guessing attacks rising as hackers pivot from OneNote vectors
News Database admins are advised to enforce better controls as attacks ending in ransomware are being observed
-
No, Microsoft SharePoint isn’t cracking users’ passwords
News The discovery sparked concerns over potentially invasive antivirus scanning practices by Microsoft
-
Microsoft Authenticator mandates number matching to counter MFA fatigue attacks
News The added layer of complexity aims to keep social engineering at bay