OAuth, Guest Accounts & Weak MFA Top SaaS Risks

▼ Summary
– Guest accounts constitute 69% of monitored SaaS accounts, outnumbering licensed users two-to-one and expanding the attack surface.
– OAuth integrations grant broad, persistent permissions that can allow attackers continued access even after password changes.
– 56% of monitored end-user accounts had MFA disabled or inactive, leaving them vulnerable to phishing and credential theft.
– External file sharing creates persistent data exposure through outdated permissions, unmanaged guest accounts, and orphaned sharing links.
– Attackers hide behind VPNs and cloud infrastructure to evade detection, while high alert volumes overwhelm security teams.
Organizations routinely set up guest accounts to provide contractors, suppliers, and partners with temporary access to files and SaaS applications. Yet many of these accounts remain active long after they are needed, creating overlooked pathways into corporate data.
Guest accounts represented 69% of all monitored SaaS accounts in 2025, a jump of more than 1.9 million over the prior year, according to Kaseya’s 2026 SaaS Security Report: Closing the Unmanaged Trust Gap. These accounts outnumber licensed users by more than two to one, dramatically expanding the attack surface. When left active and unmanaged, they give cybercriminals opportunities to compromise them through credential stuffing, password spraying, and similar methods. Guest accounts often receive the same permissions as internal employees, including privileged access.
AI-assisted account enumeration is making these attacks more efficient. Attackers use automated tools to identify active guest accounts within a tenant, test them for weaknesses, and gain entry through dormant accounts.
OAuth integrations are also widening the SaaS attack surface. Organizations are adopting AI assistants, automation tools, and collaboration platforms that integrate with Microsoft 365 and Google Workspace via OAuth. These integrations let employees sign in with existing work accounts and grant third-party applications access to email, cloud storage, calendars, messaging platforms, and other business data.
OAuth-connected applications receive broad permissions that stay active after approval. If an application is malicious or becomes compromised, attackers can maintain access through OAuth tokens without stealing passwords. This access can persist even after a user changes their password, making malicious activity hard to detect.
Weak MFA adoption leaves many accounts exposed. Multi-factor authentication remains one of the strongest defenses against account compromise, yet adoption across small and midsize businesses is limited. Fifty-six percent of monitored end-user accounts had MFA disabled or inactive, and only 27% of organizations enforced MFA policies across their SaaS environments. Accounts protected only by passwords remain vulnerable to phishing, credential theft, and password reuse. Once attackers gain access, they can operate as legitimate users within SaaS applications, raising the risk of business email compromise, fraud, and unauthorized data access.
External file sharing creates persistent data exposure. Cloud collaboration platforms make it easy for employees, contractors, partners, and customers to share files across organizational boundaries. The growing use of AI assistants and automated workflows accelerates this trend as business applications exchange data and employees connect third-party services to corporate SaaS environments.
External file sharing increases the chance that sensitive business information remains accessible after collaboration ends. Shared documents may contain financial records, customer data, internal communications, or intellectual property that remain available due to outdated permissions, unmanaged guest accounts, or orphaned sharing links. These links are often created for temporary projects and never revoked, allowing former contractors, partners, or anyone with the original URL to retain access long after the collaboration ends.
Trusted infrastructure is undermining login detection. Attackers hide behind VPNs, proxy networks, cloud infrastructure, and compromised systems to make malicious activity appear legitimate. This reduces the effectiveness of security controls that rely on IP reputation or geographic location to identify suspicious logins.
Remote work, outsourcing, and global collaboration have made unauthorized access harder to detect. Organizations expect legitimate logins from countries associated with remote employees, contractors, cloud providers, and VPN services, making it difficult to distinguish normal business activity from compromised accounts.
Growing alert volumes overwhelm security teams. SaaS environments generate billions of security events, making it hard for teams to distinguish routine business activity from malicious behavior. While most events are low priority, the report recorded nearly 279 million medium- and critical-severity alerts in 2025.
Service principal logins became a common source of critical alerts in 2025. Service principals are non-human identities used by applications, scripts, and automation tools to access SaaS services. If compromised, they can give attackers persistent access that is harder to detect than activity from standard user accounts.
“AI-emboldened threat actors see one interconnected attack environment, whereas most organizations defend their infrastructure in pieces,” said Jim Lippie, chief product officer at Kaseya. “The most resilient organizations will be those that embrace continuous monitoring, identity governance and automated response as foundational requirements.”
(Source: Help Net Security)




