Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AppOmni’s 2024 report did not find that 49% of all enterprises underestimate every kind of SaaS risk. It found that 49% of surveyed people who frequently used Microsoft 365 believed fewer than 10 applications were connected to it, while AppOmni’s aggregated deployment data indicated more than 1,000 SaaS-to-SaaS connections on average. Those are separate measures, not a like-for-like comparison. The finding points to an important question for IT and security teams: how many apps connect to your Microsoft 365 environment, and who approved them?

What the 49% figure measures

The statistic comes from AppOmni’s 2024 survey of security decision makers and managers at 644 organizations in the United States, United Kingdom, France, Germany, Japan, and Australia. Nearly half of respondents represented organizations with more than 2,500 employees. AppOmni is a SaaS security vendor, so the result is a vendor-sponsored survey, not a census of enterprises. Its August 27, 2024 announcement describes the 49% as respondents who frequently used Microsoft 365 and believed fewer than 10 applications were connected to the platform. AppOmni separately reported an average of more than 1,000 SaaS-to-SaaS connections per deployment in its aggregated data.

The two figures show a potential awareness gap, but they come from different kinds of evidence: respondents’ estimates and AppOmni’s aggregate telemetry. They do not establish that each surveyed organization had 1,000 connections, or that every connection was unauthorized or dangerous. They also do not measure the percentage of enterprises that underestimate all SaaS risks.

Another survey result points to a broader inventory problem: 34% of respondents said they did not know how many SaaS applications their organization had deployed. Without an inventory, teams may struggle to identify app owners, assess data access, or determine whether an integration is still needed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why app-to-app connections matter

SaaS connections let applications exchange data or automate work. That can be useful, but each integration may add another path to company information and another set of permissions to understand. An application can be approved for use while a particular connection, scope of access, or configuration still deserves review.

#1 Best Overall
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Business teams often adopt tools to solve immediate operational needs. Security teams need a way to discover those services and connections, understand what they can access, and establish clear ownership. AppOmni’s 2024 report announcement identifies decentralization and unclear ownership as issues in SaaS security.

A policy is not the same as enforcement

AppOmni reported that 90% of respondents said their organizations had policies limiting use to sanctioned applications. Yet 34% believed those policies were not strictly enforced in practice; AppOmni said that share was 12 percentage points higher than in 2023. A written rule cannot by itself prevent unapproved apps from being adopted or ensure that approved apps are configured safely.

Rank #2
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

The same report said 31% of respondents reported that their organization had suffered a data breach, five percentage points above the prior year. That is AppOmni’s reported breach measure; it should not be treated as a count of incidents caused by SaaS connections or as the same finding as the Microsoft 365 awareness statistic.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In AppOmni’s separate 2025 survey, 75% of more than 800 leaders said their organization had experienced a SaaS-related incident in the preceding year, according to the company’s 2025 announcement. This uses a different incident measure and a different sample from the 2024 breach result, so the figures should not be combined into a trend line.

Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Who is responsible for SaaS security?

Responsibility is shared. A SaaS provider manages parts of the service and its underlying infrastructure, but customers still make important decisions about how their organization uses the application. AppOmni’s 2024 report discusses responsibilities that remain with customers, including identity and access controls, account lifecycle management, configuration, audit-log monitoring, third-party connections, and whether their use meets applicable regulatory requirements.

Single sign-on (SSO) and multifactor authentication (MFA) help control account access, but they do not inventory integrations or ensure that every application is configured appropriately. AppOmni’s report says, “Access controls like SSO and MFA should never be optional.” Treat these as foundational controls within a broader program, not as a complete solution.

Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to reduce the visibility gap

AppOmni recommends locating sensitive data, setting baseline policies, reviewing who can access what, and monitoring continuously for policy or configuration drift. Organizations can turn those recommendations into a practical review process:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Build an inventory. Identify sanctioned and discovered SaaS applications, their business owners, and their authentication method. Include SaaS-to-SaaS integrations, not just standalone apps.
  2. Map access and data. For each application and connection, determine which users, roles, and external services can access it, what data is involved, and whether the permission is still required.
  3. Set and enforce policy. Define which applications and connection types are permitted, who can approve exceptions, and how teams will detect or address use outside the policy.
  4. Review identity and configuration. Apply SSO and MFA where available, promptly remove access when people change roles or leave, and check application settings against documented baselines.
  5. Monitor and assign ownership. Review audit logs and configuration changes on an ongoing basis. Make clear which team responds to alerts, investigates unexpected access, and follows up with the app owner.

If you assess tools for this work, compare the capabilities that matter to your program rather than relying on a category label. AppOmni’s report notes that SSPM (SaaS Security Posture Management) lacks a unified definition and organizations use a variety of tools. Useful evaluation areas include application and connection discovery, configuration enforcement and drift detection, identity and permissions coverage, audit telemetry, integration with SOC/SIEM workflows, and compliance reporting.

Best Value
Cryptnox FIDO2 Security Key with MIFARE DESFire NFC Smart Card for 2FA MFA
  • HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
  • BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
  • CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
  • DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
  • SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty

What earlier security studies add

Older studies provide context, but their figures should not be read as current prevalence estimates. The Cloud Security Alliance’s summary of its 2022 survey said at least 43% of organizations had dealt with one or more security incidents caused by SaaS misconfiguration since 2019. Respondents identified too many departments having access to settings (35%) and poor visibility into security-setting changes (34%) as leading causes. These findings reinforce the value of clear ownership and configuration monitoring, but they are not directly comparable with AppOmni’s 2024 or 2025 measures. See the Cloud Security Alliance survey summary.

A 2019 McKinsey survey of 61 respondents found that enterprise respondents prioritized encryption and key management, federated and role-based identity and access management, monitoring and logging, SOC/SIEM integration, and incident response capabilities from SaaS vendors. Its age and small sample limit what it can say about current adoption; it is useful as a list of capabilities organizations considered important, not as a present-day benchmark. See McKinsey’s survey discussion.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.