REGISTER REVISED SEPTEMBER 2026

Disconnected applications: governing apps your IdP and IGA cannot reach

ILM Reference editors · Last reviewed September 2026 · 9 minute read

SUMMARYREV. 2026-09

A disconnected application is one your identity provider or IGA cannot read from or write to: no SSO federation, no SCIM, no API connector. Its accounts are invisible to automated JML and reviews unless someone exports them. You can connect it, fulfil by ticket, automate its admin screens, or use a discovery tool that maps identity inside it, and most programs use more than one.

§ 01

What makes an application disconnected?

  • It has its own login and user table rather than federated sign-on.
  • It has no provisioning interface (SCIM, API) or one the IGA has no connector for.
  • It is on-premises, legacy or custom-built, owned by a business unit.
  • Nobody registered it with the IAM team, so it is not in the IGA at all.

The last case is the hardest: you cannot connect an application you do not know about.

§ 02

Why do disconnected apps matter?

Leavers keep access in them, local and orphan accounts accumulate in them, and audits sample them. SailPoint's own blog describes the scale of the onboarding problem: customers 'often have hundreds or thousands of applications which need to be connected'. Orchid's SailPoint partnership post puts it as governing 70% of the identity estate well while knowing nothing about the other 30%. That figure is Orchid's illustration, not a measurement.

§ 03

What are the four ways to govern them?

Four ways to govern disconnected applications.
ApproachHow it worksStrengthLimitationWho describes it
Build a connectorIn-house team or systems integrator writes code to read and write accountsFull automation for that appOne app at a time; maintained foreverC1 Baton (open source), Veza OAA, systems integrators
Ticketed or file-based fulfilmentExport accounts to CSV for reviews; open tickets for changesWorks for any app todayManual, periodic, slowMicrosoft Entra ID Governance documentation
RPASoftware drives the app's admin screensNo API neededBreaks when screens changeIdira Identity Governance (Palo Alto Networks)
Discovery and in-app identity analysisTool discovers the app and maps accounts and authentication inside it, then feeds the IGAFinds unknown apps and local accountsDoes not provision on its ownOrchid Security

Saviynt's IGA states onboarding of disconnected applications as part of the platform; the method per app should be checked in a proof of concept.

§ 04

Which approach should you start with?

Start with the inventory. Until you know which applications exist and which accounts they hold, connector and ticket work goes to the apps someone remembered. Then rank apps by risk (financial reporting scope, regulated data, privileged access) and pick the approach per app: connectors for the few that change often, tickets for low-volume apps, and discovery for the long tail.

§ 05

How do the tools compare on disconnected apps?

Disconnected-App Coverage Ledger, September 2026. What each vendor's public pages describe for an application with no connector, no SCIM endpoint and no SSO integration.
ToolDiscovery of the appAccount data collectionLeaver action on the appMethod describedSource
Orchid SecurityDocumented discovers unmanaged SaaS, cloud, on-prem, legacy and custom appsDocumented maps accounts, roles and authentication paths inside the appPartial feeds context to IAM, IGA and ITSM tools, which actDiscovery and analysis, then orchestration into existing toolsSource: orchid.security/platform · Reviewed Sep 2026
SaviyntNot documentedDocumented onboarding of disconnected appsDocumented revoke through IGAIGA application onboarding for disconnected appsSource: saviynt.com IGA page · Reviewed Sep 2026
VezaNot documentedDocumented accounts outside identity platforms, custom systems via OAADocumented offboarding including local accountsAccess Graph integrations and OAASource: veza.com lifecycle and access reviews pages · Reviewed Sep 2026
SailPoint Identity Security CloudPartial app owners self-register apps (Application Management add-on)Partial integration templatesNot documented for unconnected appsSelf-registration and templates to speed onboardingSource: sailpoint.com Application Management blog · Reviewed Sep 2026
Microsoft Entra ID GovernanceNot documentedManual process export users to CSV and match to Entra usersManual process access review, then removal or a ServiceNow ticketDocumented manual procedureSource: learn.microsoft.com not-provisioned users article · Reviewed Sep 2026
C1Partial shadow app signup and login detectionPartial Baton connectors, C1 Bridge for on-premNot documented for apps with no connectorOpen-source connectorsSource: c1.ai · Reviewed Sep 2026
LumosPartial shadow IT in identity analyticsNot documentedPartial revocation across local accounts, custom and on-prem appsIntegrations; no-API handling not detailedSource: lumos.com lifecycle page · Reviewed Sep 2026
Okta Identity GovernanceNot documentedNot documentedPartial Workflows, APIs or manual stepsWorkflows and manual processesSource: okta.com lifecycle page · Reviewed Sep 2026
Not scored: Idira Identity Governance (Palo Alto Networks)zillasecurity.com redirects to this page (checked 27 September 2026). Not scored; see Editorial method.Not documentedDocumented robotic process automation to connect to applications that lack APIsNot documentedRPASource: paloaltonetworks.com/idira/human/identity-governance · Reviewed Sep 2026

Download the ledger (CSV)

See the comparison

FAQ

Is a disconnected app the same as shadow IT?

Not exactly. Shadow IT is software the organization did not approve. A disconnected app may be fully approved and business-critical, just not integrated with identity systems.

Can an access review include a disconnected app?

Yes, if you load its accounts. Microsoft documents doing this with a CSV export and PowerShell matching before creating the review.

Sources

Reviewed Sep 2026

Related

GUIDEREV. 2026-09
COMPARISONREV. 2026-09