What Is Unauthorized Software?
Unauthorized software refers to any program, application, or operating system component installed on a network or device without approval from management or an IT security team. This can include everything from free consumer applications, to SaaS tools that have not been vetted for security or compliance, to pirated software or malware. Employees may install such software to boost productivity, bypass workflow bottlenecks, or due to negligence or malicious intent.
Unauthorized software is sometimes called “shadow IT” because it operates outside the visibility and control of official IT management. The risk increases as more employees work remotely or use personal devices for business. Without centralized oversight, organizations lose track of what software is running on their networks, which can expose them to significant security, compliance, and operational issues.
Key categories of unauthorized software:
- Shadow IT and unauthorized SaaS tools: Cloud applications and services adopted without IT approval that may bypass security reviews, access controls, and compliance requirements.
- Pirated, cracked, or unlicensed software: Software used without valid licensing or modified to bypass licensing restrictions, often carrying legal and security risks.
- Outdated unsupported software: Applications that no longer receive vendor updates or security patches, leaving known vulnerabilities unaddressed.
- Remote access and administration tools: Unapproved remote desktop, VPN, or system management tools that can create unauthorized pathways into corporate systems.
- Unauthorized developer tools: Unvetted code editors, package managers, libraries, and development utilities that may introduce security, compatibility, or supply chain risks.
- AI tools used without approval: Generative AI platforms, coding assistants, and AI agents used outside governance processes, creating data security and compliance concerns.
Threats posed by unauthorized software:
- Uncontrolled data exposure: Sensitive business information may be shared with unapproved applications that store, process, or transmit data outside organizational oversight.
- Integrity and security risk: Unauthorized software can introduce vulnerabilities, malware, insecure configurations, or unverified code into the environment.
- Governance challenges: Organizations lose visibility into software usage, making it difficult to enforce policies, manage risk, maintain compliance, and respond to incidents.
This is part of a series of articles about application control.
In this article:
- Why Is Unauthorized Software Dangerous?
- Key Categories and Examples of Unauthorized Software
- The Rising Risk of Shadow AI
- Best Practices for Managing Unauthorized Software
Why Is Unauthorized Software Dangerous?
Security Vulnerabilities
Unauthorized software often bypasses standard security reviews, vulnerability assessments, and approval processes. Because it has not been evaluated by IT or security teams, the organization may be unaware of weaknesses such as insecure default settings, poor encryption, weak authentication controls, or exposed network services.
Attackers actively search for vulnerable applications running inside corporate environments. A single unapproved application with a known security flaw can provide an entry point into the network. Once compromised, attackers may be able to move laterally, steal credentials, access sensitive systems, or deploy additional malicious tools.
Malware Infection
Software downloaded from unofficial websites, peer-to-peer networks, or untrusted vendors may contain hidden malware. Cybercriminals frequently bundle malicious code with seemingly legitimate applications, especially free software, cracked software, and browser extensions.
A malware infection can lead to data theft, ransomware attacks, system disruption, or unauthorized remote access. In many cases, employees may not realize that software is malicious because it appears to function normally. Once installed, malware can spread throughout the environment and affect multiple users and systems.
Data Leakage
Many unauthorized applications collect, process, or store data outside approved corporate systems. Employees may use file-sharing platforms, note-taking tools, messaging apps, or AI services that have not been reviewed for security or privacy risks.
Sensitive information such as customer records, financial data, intellectual property, or internal documents may be uploaded to external services without proper safeguards. Because these applications operate outside organizational oversight, IT teams may have little visibility into where data is stored, who can access it, or how long it is retained.
Loss of Access Control
Organizations rely on centralized identity and access management systems to control who can access business resources. Unauthorized software often operates independently of these controls, making it difficult to enforce security policies consistently.
Users may create accounts using personal email addresses, share credentials with coworkers, or grant access to external parties without approval. As a result, organizations can lose visibility into who has access to sensitive information. When employees leave the company, access may remain active because the software is not connected to official user management processes.
Compliance Violations
Many industries are subject to regulations governing how data is collected, processed, stored, and protected. Examples include GDPR, HIPAA, PCI DSS, SOX, and industry-specific security requirements. Unauthorized software may not meet these standards or provide the controls needed to demonstrate compliance.
The use of unapproved applications can create audit gaps and increase regulatory risk. Organizations may be unable to prove where data resides, who accessed it, or whether appropriate security measures were in place. This can result in fines, legal penalties, contractual violations, and damage to customer trust.
System Instability
Software that has not been tested within the organization's environment can interfere with existing applications, operating systems, and security controls. Different applications may compete for system resources, modify configurations, or create compatibility conflicts.
These issues can lead to slow performance, unexpected crashes, service interruptions, or failed updates. In complex environments, even a small unauthorized application can have unintended consequences that affect critical business systems and reduce overall reliability.
Lack of Updates and Support
Authorized software is typically included in patch management programs that ensure vulnerabilities are fixed promptly. Unauthorized software is often excluded from these processes because IT teams may not know it exists.
As a result, known security flaws can remain unpatched for long periods. Some unauthorized applications may also be abandoned by their developers and no longer receive updates or technical support. This leaves organizations exposed to vulnerabilities that attackers can easily exploit.
Shadow IT Risk
Unauthorized software is a common form of shadow IT, where employees adopt technology solutions without the involvement of IT departments. While these tools are often introduced to improve productivity, they create significant visibility and governance challenges.
Security teams cannot effectively monitor, secure, or manage systems they do not know about. As shadow IT grows, organizations lose a clear understanding of their technology landscape. This makes risk assessment, incident response, asset management, and security planning much more difficult.
Business Continuity Risk
Business continuity depends on reliable systems, documented processes, and effective disaster recovery planning. Unauthorized software is rarely included in backup procedures, recovery plans, or operational documentation.
If a critical unauthorized application becomes unavailable due to a cyberattack, vendor outage, hardware failure, or employee departure, important business processes may be disrupted. Because IT teams may have limited knowledge of the application, restoring operations can take significantly longer and increase downtime costs.
Key Categories and Examples of Unauthorized Software
Shadow IT and Unauthorized SaaS Tools
Shadow IT is the use of applications, software, and services without explicit approval from the IT department. Employees often deploy these tools to boost productivity or bypass strict internal processes. However, these unsanctioned tools, especially cloud-based SaaS, lack necessary enterprise-grade security controls and governance, creating serious risks for data leaks and compliance violations.
Common examples:
- File-sharing services (e.g., Dropbox or Google Drive)
- Communication platforms (e.g., WhatsApp or Slack)
- Project management apps (e.g., Trello or Asana)
Pirated, Cracked, or Unlicensed Software
This category includes software that is illegally copied, modified, or used without securing the required licensing agreements. The primary risks are two-fold: security threats from embedded malware and trojans often distributed with unauthorized copies, and legal/financial penalties. Using pirated software is a direct violation of vendor licensing and can lead to audits, heavy fines, and severe reputational damage.
Common examples:
- Illegally copied or modified software
- Cracked versions of legitimate programs
- Programs used outside the scope of their original licensing agreement
Outdated Unsupported Software
This covers applications that have passed their vendor support lifecycle and no longer receive vital security patches or updates. Continuing to run these legacy systems leaves organizations exposed, as new vulnerabilities are discovered that will remain unpatched, making them prime targets for attackers. Additionally, unsupported software creates operational risks due to increasing incompatibility with modern hardware and security tooling.
Common examples:
- Applications past their vendor support lifecycle
- Legacy applications with unpatched vulnerabilities
- Software incompatible with new hardware or operating systems
Remote Access and Administration Tools
Remote access and administration tools are designed to allow control over systems and data from external locations. When installed without proper vetting, they create critical security vulnerabilities, often providing attackers with persistent access to the internal network by bypassing perimeter defenses. Even legitimate tools become a threat if not centrally managed, as this prevents the enforcement of strong authentication, logging, and access restrictions.
Common examples:
- Unauthorized remote desktop software
- Unapproved VPN clients
- Employee-installed remote troubleshooting software
Browser Extensions
Browser extensions are small add-ons that modify or extend the functionality of web browsers. While many provide useful features, unapproved extensions can introduce significant security and privacy risks because they often require broad permissions to read website content, access browser sessions, modify web pages, or interact with downloaded files. Extensions installed without oversight may collect sensitive information, inject malicious code, track user activity, or serve as a pathway for malware.
Because extensions are frequently updated through third-party marketplaces, organizations may have limited visibility into what code is running inside employee browsers. Even legitimate extensions can become risky if they are compromised by attackers, acquired by untrusted developers, or granted excessive permissions. Managing browser extensions is therefore an important part of controlling unauthorized software and reducing attack surface.
Common examples:
- Unapproved password managers
- Shopping, coupon, and price-comparison extensions
- AI writing assistants and productivity add-ons
- Screen capture and recording extensions
- Extensions that request excessive browser permissions
- Malicious or compromised browser add-ons distributed through extension stores or third-party websites
Unauthorized Developer Tools
This category includes unapproved software such as code editors, compilers, and debuggers used in the development lifecycle. Installing these tools without oversight can introduce security vulnerabilities if they are misconfigured or contain outdated components, weakening established security practices. Furthermore, unauthorized tools can conflict with approved development environments, complicating version control and making it difficult to maintain code quality and audit activities.
Common examples:
- Unapproved code editors and compilers
- Debuggers and other testing software
- Tools that introduce compatibility or version control issues
AI Tools Used Without Approval
Unapproved AI tools, including generative platforms and machine learning services, are used increasingly by employees without IT consent. The main concerns are data privacy, compliance, and IP protection, as these tools often process sensitive business data in unvetted, third-party environments that may not meet corporate security standards. They also pose technical risks by generating flawed or insecure outputs, potentially introducing system vulnerabilities.
Common examples:
- Generative AI platforms
- AI-powered code generators and chatbots
- Agentic AI systems
The Rising Risk of Shadow AI
Shadow AI is a subset of unauthorized software involving the use of AI tools, models, and services without approval from IT, security, or compliance teams. Employees may use public generative AI platforms, AI coding assistants, transcription tools, or data analysis services to automate tasks. While these tools may offer short-term gains, they operate outside governance processes and create security and compliance concerns.
Here are some of the new and significant risks introduced by shadow AI:
Uncontrolled data exposure
Employees may submit confidential documents, source code, customer information, or internal communications to third-party AI systems. Depending on provider policies, this data may be retained, used for model training, or processed in regions that violate regulatory requirements. Organizations can lose visibility into where sensitive data is stored, how it is handled, and who can access it.
Integrity and security risks
AI-generated outputs can contain inaccurate information, insecure code, or biased recommendations that employees may trust without validation. Developers using unauthorized AI coding assistants may introduce vulnerabilities, insecure dependencies, or licensing conflicts into production systems. Because these tools are often integrated into browsers, IDEs, or cloud workflows, their usage can be difficult for security teams to detect and monitor.
Governance challenges
New AI services appear frequently, and employees can access them instantly through web browsers or plugins without installing software locally. Organizations should expand software governance strategies to include AI usage policies, approved AI tool inventories, data handling controls, and employee education programs. Monitoring outbound traffic, implementing browser controls, and deploying data loss prevention technologies can help reduce risks associated with shadow AI.
Best Practices for Managing Unauthorized Software
1. Establish a “Deny by Default” Application Control Policy
A “Deny by Default” application control policy means that only approved software can be installed or executed within the organization’s environment. This approach reduces the risk of unauthorized or malicious software running on endpoints because anything not on the allowlist is blocked. All applications are denied unless a business case is made and the software is formally evaluated and approved. This policy creates a security baseline and limits shadow IT or unvetted tools.
Implementing a Deny by Default policy requires planning and stakeholder support. IT teams should develop clear procedures for requesting, reviewing, and approving software to minimize disruption. Communication and training help employees understand why software is restricted and how to request new tools. Regular audits and automated enforcement help maintain policy effectiveness and identify attempts to bypass controls.
2. Maintain a Complete Software Inventory
Maintaining a complete and updated software inventory is necessary for identifying unauthorized software. Organizations cannot secure applications they do not know exist. An inventory should include desktop applications, SaaS services, browser extensions, mobile apps, developer tools, and remote access utilities across managed and unmanaged devices. Automated asset discovery tools can detect software installations, network activity, and cloud service usage.
Software inventories should track version numbers, licensing status, ownership, and support lifecycle information. This helps IT and security teams identify outdated, unsupported, or duplicate applications before they become a risk. Regular audits validate inventory accuracy and uncover shadow IT that bypassed procurement or installation processes. A reliable inventory supports vulnerability management, compliance reporting, and application control policies.
3. Allowlist Authorized Applications, Don’t Just Block Known Bad Software
Traditional security approaches often focus on blocking known malicious software, but this model is insufficient against modern threats and shadow IT. Allowlisting defines which applications are permitted to run within the environment. Any software not on the approved list is denied by default. This reduces the chance of unauthorized tools or malware executing on corporate systems.
Application allowlisting is effective because attackers often use legitimate tools or modified software that may not appear in blocklists or antivirus signatures. Restricting execution to approved applications prevents unvetted software from running even if it is not yet recognized as malicious. Allowlisting policies should be reviewed and updated to meet business needs while maintaining security controls.
4. Control Software at Multiple Trust Levels
Not all software carries the same level of risk, so organizations should apply controls based on trust and sensitivity. Critical applications may receive broader permissions, while newly approved or lower-trust software may operate in restricted environments with limited access to data, networks, or system resources. This layered approach reduces the impact of compromised or misconfigured applications.
Endpoint security platforms can enforce different trust levels using sandboxing, privilege restrictions, and behavior monitoring. For example, approved productivity software may have internet access but be prevented from executing scripts or accessing sensitive directories. Developer tools may require elevated privileges only within isolated environments. Segmenting software by trust level improves security without blocking needed tools.
5. Include Scripts, Installers, and Libraries in the Policy
Unauthorized software policies should extend beyond traditional applications. Scripts, installers, plugins, browser extensions, dynamic libraries, and package dependencies can introduce security risks. Attackers use scripts and lightweight tools because they are easier to hide and may bypass traditional application controls. Employees may also download unsafe libraries or automation scripts from public repositories without vetting.
Organizations should enforce controls on scripting environments such as PowerShell, Python, Bash, and JavaScript, especially in sensitive environments. Approved repositories and signed packages help ensure software integrity. Monitoring installer execution and dependency usage is also important, particularly in development environments where third-party libraries are introduced. Policies should address the full software execution chain, not only standalone applications.
6. Establish Exception Management Policies
Even with strong application control policies, organizations will occasionally need to approve software that falls outside standard requirements. Exception management provides a structured process for evaluating, documenting, approving, and reviewing these cases. Without formal exception procedures, employees may bypass controls, creating inconsistent security practices and increasing the risk of unauthorized software becoming permanently embedded in the environment.
Exception requests should include a business justification, risk assessment, software owner, approval authority, and defined review period. Security teams should evaluate factors such as vendor reputation, required permissions, data access, compliance implications, and available alternatives. Approved exceptions should be time-limited whenever possible and subject to periodic review to ensure they remain necessary. Maintaining a centralized record of exceptions improves accountability, audit readiness, and visibility into software-related risk.
7. Align Unauthorized Software Controls With Compliance Frameworks
Managing unauthorized software is also a compliance requirement in many industries. Frameworks such as NIST CSF, CIS Controls, ISO 27001, HIPAA, PCI DSS, and GDPR emphasize software inventory management, access control, patching, and application governance. Aligning software control policies with these frameworks helps organizations demonstrate due diligence and reduce regulatory risk.
Compliance alignment improves operational consistency. Standardized policies make it easier to conduct audits, generate evidence for regulators, and enforce security controls across departments. Organizations should map application control measures to regulatory requirements and review policies as frameworks evolve. Integrating unauthorized software management into governance and risk management programs supports long-term accountability.
How to Stop Unauthorized Software with Airlock Digital Application Control and Allowlisting
Airlock Digital provides enterprise-grade application control built to prevent unauthorized software from ever executing on your endpoints. By enforcing a Deny by Default model, Airlock Digital ensures that only trusted applications, scripts, and processes are permitted to run, while everything else is blocked. Designed for real-world usability, it gives administrators the proven workflows and flexible tooling needed to make application control achievable and scalable across the enterprise, so security teams can choose what they trust and block everything else.
Key capabilities of Airlock Digital:
- Deny by Default enforcement: Only trusted applications, scripts, and processes are permitted to execute, providing foundational protection against ransomware, zero-day threats, and unauthorized applications before they can run.
- Granular policy control: Define trusted applications at the file, path, publisher, or parent process level for complete control over what executes in your environment.
- Advanced exception management: Handle exceptions with flexible, rule-based overrides for specific scenarios without compromising security.
- One-Time Passwords (OTPs): Allow temporary execution of untrusted applications through a secure One-Time Password (OTP) mechanism, maintaining operational continuity while preserving security integrity.
- Integrated file-level intelligence: Leverage industry-leading VirusTotal intelligence to inform and refine allowlisting policy decisions.
- Enhanced visibility: Monitor application behavior and maintain comprehensive audit trails to support compliance.
- Scalable for all environments: Deploy policies consistently across IT, OT, and hybrid environments, including legacy systems.
Take control of exactly what runs on your endpoints and block unauthorized software at enterprise scale. Learn more about Airlock Digital Application Allowlisting.