Skip to main content

Sign-in & Sign-up Detection (Shadow IT Discovery)

Gain full visibility into SaaS sprawl across your organization. Swif’s browser extension automatically identifies when employees create accounts or sign in to third-party web applications using their work credentials, populating real-time discovery data directly into your Swif Admin Console.

Overview

As modern teams adopt new cloud tools to stay productive, unmanaged apps (“Shadow IT”) can introduce security vulnerabilities, compliance risks, and unexpected software spend.

Swif’s Sign-in & Sign-up Detection monitors authentication events in the background, instantly mapping newly accessed SaaS applications to the corresponding employee and managed device without disrupting employee workflows.

Key Features

  • Comprehensive Detection: Captures both new account registrations (sign-ups) and regular account logins (sign-ins).

  • Multi-Method Auth Support: Detects traditional email/password credentials as well as popular Single Sign-On (SSO) authentication flows (such as “Continue with Google”, “Sign in with Apple”, and “Sign in with Microsoft”).

  • Zero-Friction for Employees: On MDM-managed devices, detection runs quietly in the background without requiring the employee to sign in to the browser extension or navigate intrusive pop-ups.

  • Instant Dashboard Sync: Newly discovered tools and user accounts are automatically categorized and logged in the Swif Admin Console under Shadow IT / Discovered Apps.

How It Works

                                Employee Action
(Sign up or Sign in on third-party SaaS)


Swif Browser Extension
(Captures auth submission / SSO trigger)

┌───────────────────┴───────────────────┐
▼ ▼
MDM-Enrolled Device Unmanaged Device
(Resolves identity via agent; (Identifies user via active
no extension login required) extension login session)
│ │
└───────────────────┬───────────────────┘

Swif Admin Console
(Shadow IT & Discovered Apps Dashboard)
  1. Authentication Event: An employee visits a third-party website (e.g., GitHub, Notion, Canva) and enters their work email address to sign in/up or clicks a social/SSO login button (“Continue with Google”).

  2. Context Resolution:

    • On MDM-Managed Devices: The browser extension communicates with the local Swif MDM agent to securely link the device and employee identity—no browser extension login is needed.

    • On Unmanaged Devices: The extension identifies the employee via their authenticated extension session.

  3. Telemetry & Categorization: The extension securely registers the service domain, application name, employee identity, and timestamp with Swif.

  4. Admin Visibility: The application and employee profile are updated under Shadow IT in your Admin Console.

Managing Discovery Settings

Admins can customize how sign-ins and sign-ups are handled across the workspace:

  1. Log in to the Swif Admin Console.

  2. Navigate to Settings > Security & Extensions (or Shadow IT Settings).

  3. Locate Automatically track app sign-ins and sign-ups:

    • Enabled (Default): Silently and automatically logs all work-account app access to Shadow IT.

    • Disabled: Disables silent tracking and presents employees with a lightweight browser prompt asking them whether they want to log each new app account.

What Admins See in the Console

Under the Shadow IT section of your admin portal, you can review:

  • Discovered SaaS Applications: A complete list of all cloud services accessed across your organization.

  • Active Users & Accounts: Which specific team members have created accounts or logged in to each tool.

  • First & Last Seen Dates: Timestamps indicating when an app was first accessed and when it was most recently used.

  • Risk & Compliance Posture: Identify unvetted services, duplicate software licenses, and potential data leakage points.

Employee Experience

Scenario

What the Employee Experiences

MDM-Managed Device (Auto-track Enabled)

Completely silent and seamless. The employee logs in or signs up normally without any alerts or disruption.

MDM-Managed Device (Auto-track Disabled)

A small browser prompt appears upon sign-in/sign-up asking whether to register this app with IT.

Unmanaged / BYOD Device

Works seamlessly as long as the employee is signed in to the Swif browser extension.


Frequently Asked Questions (FAQ)

Does it capture employee passwords?

No. Swif only detects that an authentication attempt took place using a company work email. Swif never inspects, captures, transmits, or stores plain-text passwords or secret credentials.

Does it track personal email logins?

No. Detection filters specifically for your organization’s work email domains. Personal logins (e.g., personal @gmail.com or @yahoo.com accounts) are ignored.

Does SSO login (e.g., "Continue with Google") get detected?

Yes. Both direct form submissions (email + password) and third-party SSO redirect buttons are tracked and attributed to the appropriate employee.

Does the employee need to be logged in to the Swif extension?

Not on MDM-managed devices. The extension leverages the local device context from the Swif MDM agent, so employees never need to manually sign in to the extension for discovery to work.

Did this answer your question?