Disconnected applications: governing apps your IdP and IGA cannot reach
ILM Reference editors · Last reviewed September 2026 · 9 minute read
A disconnected application is one your identity provider or IGA cannot read from or write to: no SSO federation, no SCIM, no API connector. Its accounts are invisible to automated JML and reviews unless someone exports them. You can connect it, fulfil by ticket, automate its admin screens, or use a discovery tool that maps identity inside it, and most programs use more than one.
What makes an application disconnected?
- It has its own login and user table rather than federated sign-on.
- It has no provisioning interface (SCIM, API) or one the IGA has no connector for.
- It is on-premises, legacy or custom-built, owned by a business unit.
- Nobody registered it with the IAM team, so it is not in the IGA at all.
The last case is the hardest: you cannot connect an application you do not know about.
Why do disconnected apps matter?
Leavers keep access in them, local and orphan accounts accumulate in them, and audits sample them. SailPoint's own blog describes the scale of the onboarding problem: customers 'often have hundreds or thousands of applications which need to be connected'. Orchid's SailPoint partnership post puts it as governing 70% of the identity estate well while knowing nothing about the other 30%. That figure is Orchid's illustration, not a measurement.
What are the four ways to govern them?
| Approach | How it works | Strength | Limitation | Who describes it |
|---|---|---|---|---|
| Build a connector | In-house team or systems integrator writes code to read and write accounts | Full automation for that app | One app at a time; maintained forever | C1 Baton (open source), Veza OAA, systems integrators |
| Ticketed or file-based fulfilment | Export accounts to CSV for reviews; open tickets for changes | Works for any app today | Manual, periodic, slow | Microsoft Entra ID Governance documentation |
| RPA | Software drives the app's admin screens | No API needed | Breaks when screens change | Idira Identity Governance (Palo Alto Networks) |
| Discovery and in-app identity analysis | Tool discovers the app and maps accounts and authentication inside it, then feeds the IGA | Finds unknown apps and local accounts | Does not provision on its own | Orchid Security |
Saviynt's IGA states onboarding of disconnected applications as part of the platform; the method per app should be checked in a proof of concept.
Which approach should you start with?
Start with the inventory. Until you know which applications exist and which accounts they hold, connector and ticket work goes to the apps someone remembered. Then rank apps by risk (financial reporting scope, regulated data, privileged access) and pick the approach per app: connectors for the few that change often, tickets for low-volume apps, and discovery for the long tail.
How do the tools compare on disconnected apps?
| Tool | Discovery of the app | Account data collection | Leaver action on the app | Method described | Source |
|---|---|---|---|---|---|
| Orchid Security | Documented discovers unmanaged SaaS, cloud, on-prem, legacy and custom apps | Documented maps accounts, roles and authentication paths inside the app | Partial feeds context to IAM, IGA and ITSM tools, which act | Discovery and analysis, then orchestration into existing tools | Source: orchid.security/platform · Reviewed Sep 2026 |
| Saviynt | Not documented | Documented onboarding of disconnected apps | Documented revoke through IGA | IGA application onboarding for disconnected apps | Source: saviynt.com IGA page · Reviewed Sep 2026 |
| Veza | Not documented | Documented accounts outside identity platforms, custom systems via OAA | Documented offboarding including local accounts | Access Graph integrations and OAA | Source: veza.com lifecycle and access reviews pages · Reviewed Sep 2026 |
| SailPoint Identity Security Cloud | Partial app owners self-register apps (Application Management add-on) | Partial integration templates | Not documented for unconnected apps | Self-registration and templates to speed onboarding | Source: sailpoint.com Application Management blog · Reviewed Sep 2026 |
| Microsoft Entra ID Governance | Not documented | Manual process export users to CSV and match to Entra users | Manual process access review, then removal or a ServiceNow ticket | Documented manual procedure | Source: learn.microsoft.com not-provisioned users article · Reviewed Sep 2026 |
| C1 | Partial shadow app signup and login detection | Partial Baton connectors, C1 Bridge for on-prem | Not documented for apps with no connector | Open-source connectors | Source: c1.ai · Reviewed Sep 2026 |
| Lumos | Partial shadow IT in identity analytics | Not documented | Partial revocation across local accounts, custom and on-prem apps | Integrations; no-API handling not detailed | Source: lumos.com lifecycle page · Reviewed Sep 2026 |
| Okta Identity Governance | Not documented | Not documented | Partial Workflows, APIs or manual steps | Workflows and manual processes | Source: okta.com lifecycle page · Reviewed Sep 2026 |
| Not scored: Idira Identity Governance (Palo Alto Networks)zillasecurity.com redirects to this page (checked 27 September 2026). Not scored; see Editorial method. | Not documented | Documented robotic process automation to connect to applications that lack APIs | Not documented | RPA | Source: paloaltonetworks.com/idira/human/identity-governance · Reviewed Sep 2026 |
FAQ
Is a disconnected app the same as shadow IT?
Not exactly. Shadow IT is software the organization did not approve. A disconnected app may be fully approved and business-critical, just not integrated with identity systems.
Can an access review include a disconnected app?
Yes, if you load its accounts. Microsoft documents doing this with a CSV export and PowerShell matching before creating the review.
Sources
- SailPoint Application Management blog
- Orchid Security, SailPoint partnership
- Microsoft Learn, apps that do not support provisioning
- C1
- Veza lifecycle management
- Idira Identity Governance
- Saviynt IGA
Reviewed Sep 2026