Module 5d — Shadow IT Discovery & AI Security Adoption
Mục tiêu: Thấy mọi ứng dụng SaaS và AI mà mọi người thực sự dùng, quyết định cái nào được phê duyệt, và thực thi quyết định đó tự động — biến "shadow IT" vô hình (và shadow AI) thành việc sử dụng được quản trị, kiểm soát bằng chính sách.
|
|
| 👤 Ai làm việc này |
Đội bảo mật / IT |
| ⏱️ Thời gian |
~40 phút (cộng một giai đoạn giám sát) |
| 🎯 Kết thúc bạn sẽ có |
Một kho ứng dụng đã rà soát với trạng thái phê duyệt, và các chính sách Gateway hành động trên chúng |
| ✋ Trước khi bắt đầu |
Đã xong Module 5 — thiết bị ở chế độ Gateway with WARP với TLS decryption on (Shadow IT được xây từ lưu lượng Gateway HTTP) |
🧭 Shadow IT là gì? Các ứng dụng nhân viên tự dùng mà không có sự phê duyệt của IT — một Dropbox cá nhân, một chatbot AI chưa được cho phép, một trang chuyển đổi tệp ngẫu nhiên. Bạn không thể bảo mật thứ bạn không thấy. Shadow IT Discovery biến log lưu lượng của Gateway thành một kho đầy đủ các ứng dụng đang dùng, để bạn đưa chúng vào kiểm soát. Đây là bước then chốt trong việc thay thế VPN: thay vì tin tưởng ngầm mọi thứ trên mạng, bạn đưa ra quyết định cho phép/chặn có chủ đích theo từng ứng dụng.
Hành trình áp dụng (cách mô-đun này vận hành)
1 DISCOVER → 2 REVIEW → 3 ENFORCE → 4 GOVERN AI
see what's approve / act on the apply the same
actually unapprove status in pattern to
in use each app Gateway AI apps + DLP
Bạn sẽ làm Discover → Review → Enforce cho SaaS nói chung (Phần A–C), rồi áp dụng cùng kỹ năng cho AI security adoption (Phần D).
Phần A — Khám phá những gì đang được dùng
- 👉 Trong bảng điều khiển, vào Insights → Analytics → Shadow IT Discovery (cũng xuất hiện qua Application Library).
- 📺 Bạn sẽ thấy: bảng điều khiển SaaS analytics đã nâng cấp — mọi ứng dụng phát hiện trong lưu lượng của bạn, với:
- ai đang dùng từng ứng dụng (người dùng),
- bao nhiêu dữ liệu đang được truyền tới nó (khối lượng),
- loại/danh mục của ứng dụng (vd. Artificial Intelligence, Social Media, Cloud Storage).
- 👉 Lọc theo application type để tập trung rà soát — vd. đặt loại thành Artificial Intelligence để thấy mọi công cụ AI đang dùng.
✅ Điểm kiểm tra: bạn thấy được danh sách ứng dụng xếp hạng kèm người dùng và khối lượng dữ liệu. (Ít/không có dữ liệu? Xác nhận thiết bị ở chế độ Gateway with WARP với TLS decryption — Module 5 — để lưu lượng HTTP được ghi log.)
💡 Hãy để nó chạy. Cho discovery một hoặc hai tuần lưu lượng thực trước khi ra quyết định, để kho của bạn phản ánh các mẫu sử dụng thật.
Phần B — Rà soát & đặt trạng thái phê duyệt
Mỗi ứng dụng có thể mang một trong bốn trạng thái phê duyệt. Đây là quyết định quản trị của bạn, được ghi theo từng ứng dụng:
| Trạng thái |
Ý nghĩa |
Dùng điển hình |
| Unreviewed |
Chưa đánh giá (mặc định) |
Điểm khởi đầu cho ứng dụng mới thấy |
| In Review |
Đang được IT/bảo mật đánh giá |
Ứng dụng bạn đang quyết định — thường được cách ly trong lúc rà soát |
| Approved |
Được cho phép sử dụng |
Các công cụ chính thức của bạn |
| Unapproved |
Không được phép |
Ứng dụng rủi ro hoặc trùng lặp cần chặn |
- 👉 Trong Shadow IT Discovery (hoặc Application Library → Review applications), mở một ứng dụng.
- 👉 Đặt approval status — vd. đánh dấu bộ công cụ được cho phép là Approved, đánh dấu một trang chia sẻ tệp rủi ro là Unapproved, và đặt bất kỳ thứ gì bạn còn đang đánh giá thành In Review.
- 👉 Làm lần lượt danh sách theo khối lượng dữ liệu / số người dùng — mức dùng lớn nhất trước.
✅ Điểm kiểm tra: các ứng dụng dùng nhiều nhất mỗi cái đều có trạng thái có chủ đích (không phải tất cả "Unreviewed").
💡 Mẹo: lôi chủ sở hữu ứng dụng vào sớm. Một công cụ "shadow" với mức dùng cao thường báo hiệu một nhu cầu thật chưa được đáp ứng — phê duyệt một tương đương an toàn tốt hơn một lệnh chặn thô.
Phần C — Thực thi quyết định bằng Gateway
Trạng thái phê duyệt trở nên mạnh khi một chính sách Gateway HTTP hành động trên nó — để các quyết định tự thực thi khi ứng dụng mới xuất hiện.
- 👉 Gateway → Firewall Policies → HTTP → Add a policy.
- 👉 Dùng selector Application Approval Status (API:
any(app.statuses[*] == "unapproved")).
Ví dụ chính sách:
| Chính sách |
Selector / value |
Action |
Block unapproved apps |
Application Status is Unapproved |
Block |
Isolate apps in review |
Application Status is In Review |
Isolate (remote browser — Module 5c) |
Limit uploads to unapproved |
Application Status Unapproved + Upload |
Chỉ Block upload |
- 👉 Bắt đầu chính sách chặn với tư duy monitor — rà log Gateway vài ngày để bắt dương tính giả — rồi mới bật thực thi.
✅ Điểm kiểm tra: duyệt tới một ứng dụng bạn đánh dấu Unapproved hiện trang chặn Cloudflare; một ứng dụng In Review mở trong remote browser được cách ly; ứng dụng Approved hoạt động bình thường.
⭐ Quản trị tự duy trì: vì chính sách nhắm vào trạng thái chứ không phải ứng dụng được đặt tên, đánh dấu bất kỳ ứng dụng tương lai nào "Unapproved" sẽ chặn nó ngay — không cần sửa chính sách.
Phần D — AI security adoption
Công cụ AI là danh mục shadow IT tăng nhanh nhất — và có rủi ro cao nhất, vì nhân viên dán dữ liệu nhạy cảm vào chúng. Áp dụng mẫu discover→review→enforce riêng cho AI, theo năm bước.
D1 — Xác định mức chấp nhận rủi ro AI (quyết định trước)
Trước khi cấu hình bất cứ gì, thống nhất chiến lược:
- AI được cho phép vs. shadow AI: bạn đang bật các công cụ AI đã phê duyệt, hay chủ yếu lo về những cái chưa được cho phép? (Nhớ: nhà cung cấp SaaS đã phê duyệt có thể có tính năng AI nhúng sẵn cũng mang rủi ro.)
- Độ nhạy của dữ liệu: loại dữ liệu nào không bao giờ được vào prompt AI? (Gắn với công việc DLP của bạn — Module 6.)
- Khuyến khích hay hạn chế: bạn muốn thúc đẩy dùng AI an toàn, hay hạn chế nó? Điều này quyết định chính sách của bạn thoáng đến mức nào.
D2 — Khám phá shadow AI
👉 Trong Shadow IT Discovery, lọc application type thành Artificial Intelligence (Phần A) — bạn giờ thấy đúng những công cụ AI nào (ChatGPT, Gemini, Claude, Perplexity, Copilot…) đang được dùng, bởi ai, và mức độ ra sao.
D3 — Rà soát & phê duyệt ứng dụng AI
👉 Đặt trạng thái phê duyệt (Phần B): Approve nền tảng AI được cho phép của bạn, đánh dấu những cái khác Unapproved hoặc In Review.
D4 — Kiểm soát việc dùng AI (quản trị, đừng chỉ chặn)
👉 Trong chính sách Gateway HTTP, áp dụng cách tiếp cận sử dụng AI hợp lệ từ Module 7:
- Cho phép AI đã phê duyệt + lan can — cho phép ứng dụng nhưng chặn hành động rủi ro (file upload) qua application granular controls.
- Chặn hoặc cách ly AI chưa phê duyệt bằng selector Application Approval Status (Phần C).
D5 — Bảo vệ prompt bằng DLP
👉 Thêm AI prompt protection — DLP kiểm tra những gì người dùng gõ vào công cụ AI và chặn nội dung nhạy cảm (PII, mã nguồn, bí mật). Xem Module 7 Phần C và Module 6 (DLP).
⭐ Thực hành tốt — đừng chặn cứng AI ngay. Lệnh cấm toàn bộ đẩy người ta sang thiết bị cá nhân nơi bạn không có tầm nhìn. Khám phá → cho phép một lựa chọn tốt → đặt lan can → bảo vệ prompt giữ AI vừa năng suất vừa an toàn.
✅ Điểm kiểm tra: việc dùng AI hiện theo ứng dụng và người dùng; AI đã phê duyệt hoạt động với lan can; AI chưa phê duyệt bị chặn/cách ly; prompt nhạy cảm bị DLP bắt.
✅ Hoàn thành Module 5d!
Bây giờ bạn có:
- ✅ Tầm nhìn đầy đủ về ứng dụng SaaS và AI đang dùng (người dùng + khối lượng dữ liệu)
- ✅ Trạng thái phê duyệt có chủ đích trên các ứng dụng hàng đầu
- ✅ Chính sách Gateway tự duy trì hành động theo trạng thái
- ✅ Một lộ trình AI security adoption: mức chấp nhận rủi ro → khám phá → rà soát → kiểm soát → bảo vệ
Cách điều này kết nối
Khắc phục nhanh
| Vấn đề |
Cách khắc phục |
| Shadow IT Discovery hiện ít/không có dữ liệu |
Thiết bị phải ở chế độ Gateway with WARP với TLS decryption bật (Module 5) — nó được xây từ log HTTP |
| Thiếu selector Application Approval Status |
Đặt trạng thái của ít nhất một ứng dụng trước; xác nhận bạn đang chỉnh chính sách HTTP |
| Ứng dụng Approved vẫn bị chặn |
Một chính sách Unapproved/Block rộng hơn nằm phía trên — sắp xếp lại (chính sách đi từ trên xuống) |
| Ứng dụng AI không xuất hiện dưới loại AI |
Cho discovery thêm lưu lượng/thời gian; xác nhận giải mã để ứng dụng được nhận diện |
| Người dùng vòng qua lệnh chặn |
Ưu tiên isolate + lan can + DLP hơn chặn cứng (Phần D) |
Phát hiện và ngăn dữ liệu nhạy cảm rời đi — kể cả vào các ứng dụng AI bạn vừa khám phá.
Module 5d — Shadow IT Discovery & AI Security Adoption
Goal: See every SaaS and AI app your people actually use, decide which are approved, and enforce that decision automatically — turning invisible "shadow IT" (and shadow AI) into governed, policy-controlled usage.
|
|
| 👤 Who does this |
Security / IT team |
| ⏱️ Time |
~40 minutes (plus a monitoring period) |
| 🎯 You'll finish with |
A reviewed app inventory with approval statuses, and Gateway policies that act on them |
| ✋ Before you begin |
Module 5 done — devices in Gateway with WARP with TLS decryption on (Shadow IT is built from Gateway HTTP traffic) |
🧭 What is Shadow IT? The apps employees adopt without IT's approval — a personal Dropbox, an unsanctioned AI chatbot, a random file-converter site. You can't secure what you can't see. Shadow IT Discovery turns Gateway's traffic logs into a full inventory of the apps in use, so you can bring them under control. This is a key step in replacing your VPN: instead of implicitly trusting everything on the network, you make deliberate allow/block decisions per app.
The adoption journey (how this module flows)
1 DISCOVER → 2 REVIEW → 3 ENFORCE → 4 GOVERN AI
see what's approve / act on the apply the same
actually unapprove status in pattern to
in use each app Gateway AI apps + DLP
You'll do Discover → Review → Enforce for SaaS generally (Parts A–C), then apply the same muscle to AI security adoption (Part D).
Part A — Discover what's in use
- 👉 In the dashboard, go to Insights → Analytics → Shadow IT Discovery (also surfaced via the Application Library).
- 📺 What you'll see: the upgraded SaaS analytics dashboard — every application detected in your traffic, with:
- who is using each app (users),
- how much data is being transferred to it (volume),
- the app's type/category (e.g. Artificial Intelligence, Social Media, Cloud Storage).
- 👉 Filter by application type to focus a review — e.g. set the type to Artificial Intelligence to see all AI tools in use.
✅ Checkpoint: you can see a ranked list of apps with users and data volumes. (Little/no data? Confirm devices are in Gateway with WARP with TLS decryption — Module 5 — so HTTP traffic is logged.)
💡 Let it run. Give discovery a week or two of real traffic before making decisions, so your inventory reflects genuine usage patterns.
Part B — Review & set approval status
Every app can carry one of four approval statuses. This is your governance decision, recorded per app:
| Status |
Meaning |
Typical use |
| Unreviewed |
Not yet assessed (default) |
Starting point for newly-seen apps |
| In Review |
Being evaluated by IT/security |
Apps you're deciding on — often isolated while reviewing |
| Approved |
Sanctioned for use |
Your official tools |
| Unapproved |
Not allowed |
Risky or redundant apps to block |
- 👉 In Shadow IT Discovery (or Application Library → Review applications), open an application.
- 👉 Set its approval status — e.g. mark your sanctioned suite Approved, mark a risky file-sharing site Unapproved, and set anything you're still assessing to In Review.
- 👉 Work down the list by data volume / user count — the biggest usage first.
✅ Checkpoint: your most-used apps each have a deliberate status (not all "Unreviewed").
💡 Tip: involve app owners early. A "shadow" tool with heavy usage often signals a real unmet need — approving a secure equivalent beats a blunt block.
Part C — Enforce the decision with Gateway
Approval status becomes powerful when a Gateway HTTP policy acts on it — so decisions enforce themselves as new apps appear.
- 👉 Gateway → Firewall Policies → HTTP → Add a policy.
- 👉 Use the Application Approval Status selector (API:
any(app.statuses[*] == "unapproved")).
Example policies:
| Policy |
Selector / value |
Action |
Block unapproved apps |
Application Status is Unapproved |
Block |
Isolate apps in review |
Application Status is In Review |
Isolate (remote browser — Module 5c) |
Limit uploads to unapproved |
Application Status Unapproved + Upload |
Block upload only |
- 👉 Start the block policy in a monitor mindset — review Gateway logs for a few days to catch false positives — then enable enforcement.
✅ Checkpoint: browsing to an app you marked Unapproved shows the Cloudflare block page; an In Review app opens in an isolated remote browser; Approved apps work normally.
⭐ Self-maintaining governance: because the policy targets status rather than named apps, marking any future app "Unapproved" instantly blocks it — no policy edits needed.
Part D — AI security adoption
AI tools are the fastest-growing category of shadow IT — and the highest-stakes, because employees paste sensitive data into them. Apply the discover→review→enforce pattern specifically to AI, in five steps.
D1 — Define your AI risk tolerance (decide first)
Before configuring anything, align on strategy:
- Sanctioned vs. shadow AI: are you enabling approved AI tools, or mainly worried about unapproved ones? (Remember: approved SaaS vendors may have embedded AI features that also carry risk.)
- Data sensitivity: which data types must never enter an AI prompt? (Ties to your DLP work — Module 6.)
- Encourage or limit: do you want to promote safe AI use, or restrict it? This sets how permissive your policies are.
D2 — Discover shadow AI
👉 In Shadow IT Discovery, filter application type to Artificial Intelligence (Part A) — you now see exactly which AI tools (ChatGPT, Gemini, Claude, Perplexity, Copilot…) are used, by whom, and how heavily.
D3 — Review & approve AI apps
👉 Set approval statuses (Part B): Approve your sanctioned AI platform, mark others Unapproved or In Review.
D4 — Control AI usage (govern, don't just block)
👉 In Gateway HTTP policies, apply the AI acceptable-use approach from Module 7:
- Allow approved AI + guardrails — permit the app but block risky actions (file upload) via application granular controls.
- Block or isolate unapproved AI using the Application Approval Status selector (Part C).
D5 — Protect prompts with DLP
👉 Add AI prompt protection — DLP inspects what users type into AI tools and blocks sensitive content (PII, source code, secrets). See Module 7 Part C and Module 6 (DLP).
⭐ Best practice — don't hard-block AI outright. Blanket bans push people to personal devices where you have zero visibility. Discover → sanction a good option → guardrail it → protect prompts keeps AI productive and safe.
✅ Checkpoint: AI usage is visible by app and user; approved AI works with guardrails; unapproved AI is blocked/isolated; sensitive prompts are caught by DLP.
✅ Module 5d complete!
You now have:
- ✅ Full visibility into SaaS and AI apps in use (users + data volume)
- ✅ Deliberate approval statuses on your top apps
- ✅ Self-maintaining Gateway policies that act on status
- ✅ An AI security adoption path: risk tolerance → discover → review → control → protect
How this connects
Quick troubleshooting
| Problem |
Fix |
| Shadow IT Discovery shows little/no data |
Devices must be in Gateway with WARP with TLS decryption on (Module 5) — it's built from HTTP logs |
| Application Approval Status selector missing |
Set at least one app's status first; confirm you're editing an HTTP policy |
| Approved app still blocked |
A broader Unapproved/Block policy sits above it — reorder (policies are top-down) |
| AI apps not appearing under the AI type |
Give discovery more traffic/time; confirm decryption so the app is identified |
| Users route around a block |
Prefer isolate + guardrails + DLP over hard blocks (Part D) |
Detect and stop sensitive data from leaving — including into the AI apps you just discovered.
Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev
Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev