Close Menu
TechurzTechurz
    What's Hot

    Future of Digital Privacy and Security: 7 Truths Nobody Tells You

    May 25, 2026

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 2026

    Peec, one of Berlin’s rising startups, more than doubled annualized revenue in months to $10M, sources say

    May 23, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Future of Digital Privacy and Security: 7 Truths Nobody Tells You
    • SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest
    • Peec, one of Berlin’s rising startups, more than doubled annualized revenue in months to $10M, sources say
    • This young startup is taking on a fragrance industry that hasn’t changed in a almost half century
    • Maka Kids is redefining kids’ screen time with a streaming app optimized for well-being, not engagement
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Security - LastPass can now monitor employees’ rogue reliance on shadow SaaS – including AI tools
    Security

    LastPass can now monitor employees’ rogue reliance on shadow SaaS – including AI tools

    TechurzBy TechurzMay 14, 2025No Comments5 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    LastPass can now monitor employees' rogue reliance on shadow SaaS - including AI tools
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Petri Oeschger/Getty Images

    With LastPass’s browser extension for password management already well-positioned to observe — and even restrict — employee web usage, the security company has announced that it’s diversifying into SaaS monitoring for small to midsize enterprises (SMEs). 

    SaaS monitoring is part of a larger technology category known as SaaS Identity and Access Management, or SaaS IAM. 

    As more employees are drawn to AI to improve productivity, the company is pitching an affordable solution to help SMEs contain the risks and costs associated with shadow SaaS; an umbrella of rogue SaaS procurement that’s inclusive of shadow IT and its latest variant — shadow AI.   

    Also: 10 passkey survival tips: Prepare for your passwordless future now

    Compared to the $7 per user per month rate that LastPass charges for its Business Edition tier, the new Business Max tier — which includes the SaaS monitoring capability — will cost $9 per user per month. 

    “Detecting which employees are accessing which applications is actually a solved problem,” LastPass chief product officer Don MacLennan told ZDNET. “Except that it’s solved by really expensive and really complex technologies that a large enterprise would use, but that a mid-size enterprise can’t afford.”

    According to MacLennan, LastPass currently serves organizations ranging in size from 20 to “a few thousand” employees, and the main reason those companies need a password manager is due to the proliferation of SaaS applications across the enterprise. In order to minimize the risks associated with poor password hygiene, organizations turn to password managers as a means of enforcing credential management best practices. 

    Also: Your password manager is under attack: How to defend yourself against a new threat

    Not only are password managers already in the critical path of SaaS application access, but the password management extensions that almost all users install into their web browsers have the necessary superpowers to both read, manipulate (alter), and autofill every web page that a user visits. When installing a password manager extension into Chrome, for example, the browser typically asks the user to grant permission for that extension to “read and change all your data on all websites,” as shown in the partial screenshot below. 

    Screenshot by David Berlind/ZDNET

    Without installing any new management agents, password manager extensions already have the power to observe and document everything a user is doing with their web browser and disrupt a user’s attempt to engage with organizationally unsanctioned SaaS sites. 

    As an example, an organization trying to keep a lid on usage of unsanctioned AI applications — i.e., shadow AI — could use LastPass’ SaaS monitoring solution to identify where employees are logging into approved versus unapproved applications and take whatever risk reduction actions are deemed necessary. 

    Also: If we want a passwordless future, let’s get our passkey story straight

    According to IBM’s research on the risks of shadow data and shadow AI, “various stakeholders in the organization can easily expose it to unmanaged risk linked with unsanctioned data, [AI] models, and overall use of AI. These uses can be invisible to the IT and security teams.” IBM’s findings align to those of Gartner’s research which stated that “by 2027, 75% of employees will acquire, modify or create technology outside IT’s visibility – up from 41% in 2022.”

    LastPass sees the new capabilities aligning with an organization’s business objectives in a variety of ways.

     “One could be compliance,” MacLennan told ZDNET. “Another could be the organization’s internal sense of risk and risk management. Another could be cost because we’re surfacing apps by category, in which case you’ll see the whole universe of duplicative apps in use.”

    MacLennan also noted that the new offering makes it easy to reduce costs due to the over-provisioning of SaaS licenses. For example, an organization is paying for 100 seats of some SaaS solution while the SaaS monitoring tool reveals that only 30 of those licenses are in active use. 

    Also: The best password managers: Expert tested

    LastPass isn’t the first password management solution provider to venture into the adjacent category of SaaS IAM. Earlier this year, 1Password diversified its solution portfolio with its acquisition of Trelica. 

    The screenshot below offers an example of the analytics LastPass administrators might see when viewing its SaaS monitoring dashboard. For example, it offers at-a-glance statistics about how users are logging into their SaaS apps — via single sign-on through a solution like Okta, via passkey, or via password. As a part of a risk management exercise, an IT department could use data like this to drive more employees to access organizationally sanctioned apps via SSO or passkeys versus the riskier usage of passwords. Additionally, the dashboard reveals the extent to which users are leveraging LastPass to manage their credentials versus riskier manual approaches to password management.

    LastPass

    The new solution does have its limitations. For example, compared to desktop and mobile agents that can monitor all desktop and SaaS app usage (i.e., not just web apps), the LastPass web extension’s visibility is limited to any SaaS apps accessed through a desktop web browser. 

    How might LastPass evolve its SaaS monitoring capability? MacLennan discussed a few options but noted that the company is not yet committing to a roadmap. 

    “You could use this to guide users away from unproductive time or harmful or malicious sites,” he said. “Some companies might want to guide employees away from social media during work hours or accessing adult content due to the company’s acceptable use policy.” He noted the possibility of future integrations with directory services like Microsoft Entra for the purpose of access control policy setting and enforcement based on a user’s workgroup or team membership. 

    Stay ahead of security news with Tech Today, delivered to your inbox every morning.

    Employees including LastPass monitor reliance rogue SaaS shadow tools
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe iPhone 18’s edgeless curved display seems like a certainty now
    Next Article Google offers AI certification for business leaders now – and the training is free
    Techurz
    • Website

    Related Posts

    Opinion

    Beehiiv rolls out new creator tools, including webinars and customizable paywalls

    April 23, 2026
    Opinion

    Hightouch reaches $100M ARR fueled by marketing tools powered by AI

    April 16, 2026
    Opinion

    Tools for founders to navigate and move past conflict

    March 19, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,289

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202517

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202614
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.