TD SYNNEX Newsflash

69% of SaaS accounts are unmanaged guest users, report finds

Cybersecurity
By TD SYNNEX Newsflash 4th September 2026

Unmanaged guest accounts, MFA gaps, and external file sharing are expanding the SMB attack surface, according to Kaseya’s latest SaaS Security Report.

One of the biggest challenges SMBs face when managing cloud security is controlling guest access. While external access is often necessary for collaboration, unmanaged accounts can also create opportunities for attackers. Kaseya’s 2026 SaaS Security Report highlights the scale of the issue and the growing risks associated with identity-based attacks.

69% of SaaS accounts are unmanaged guest users, report finds

Key findings from the report

  • 69% of monitored accounts were unmanaged guest accounts, potentially exposing organisations to unnecessary access and data risks.
  • Multi-factor authentication (MFA) remains underused, with 56% of accounts lacking active MFA and only 27% of SMBs enforcing it organisation-wide.
  • External file sharing continues to increase data exposure, particularly within Microsoft 365 environments.

The report suggests threat actors are moving away from traditional perimeter attacks and focusing on identities, open authorisations and collaboration workflows. As AI-driven attacks become more sophisticated and coordinated, organisations need greater visibility into who and what has access to their environments.

The rise of machine identities and AI-driven threats

Rapid AI adoption is accelerating the use of third-party authorisations that often rely on persistent tokens rather than credentials. These tokens can retain data access even after a password reset.

As a result, non-human service principal logins now account for 20% of critical security alerts. At the same time, attackers are increasingly using AI-powered automation to identify and exploit dormant guest accounts.

Legacy security controls are losing effectiveness

Traditional controls, including location-based blocking, are proving less effective as attackers use trusted cloud services and VPNs to disguise their origins. Once access is gained, weak identity controls can make it easier to move undetected within an environment and access sensitive data.

Combined with growing levels of file sharing, these gaps create opportunities for attackers to exfiltrate information without triggering traditional security controls.

Additional findings

  • Microsoft 365 exposure: Nearly 45% of shared files in Microsoft 365 environments were shared outside the organisation.
  • Alert fatigue: Although 98.9% of monitored security events in 2025 were classified as low severity, organisations still faced more than 278 million medium- and critical-severity alerts requiring investigation.

Closing the security gap

The report recommends moving beyond perimeter-focused security towards an identity-first approach built on stronger governance. Key actions include continuous monitoring, automated behavioural analysis, organisation-wide MFA enforcement, and regular auditing of machine identities and external sharing permissions.

Kaseya analysed more than 27.6 billion SaaS security events across more than 50,000 SMB environments, including 5,400 MSP partners and 6.2 million end-user accounts.

The TD SYNNEX security practice is available to help partners strengthen customer security strategies and reduce identity-related risk across cloud environments.