Skip to main content
Has your work email already leaked?Run the 10-second check
Glossary

SSPM SaaS Security Posture Management

What is SSPM?

Configuration drift monitoring across SaaS apps (M365, Google Workspace, Salesforce, Slack, GitHub). Detects misconfigurations, OAuth abuse and shadow SaaS.

Every significant SaaS application ships hundreds of security-relevant settings, and each is a place where posture can quietly regress. External sharing defaults, legacy authentication protocols, guest access, admin role assignment, audit logging, retention and multi-factor enforcement all sit in different consoles with different vocabulary. SSPM watches those settings continuously and reports drift against a baseline instead of relying on someone remembering to re-check.

The part organizations most often miss is OAuth. Users can grant third-party applications standing access to mailboxes and files without any administrator involved, and that access persists after the user changes their password, leaves the company, or forgets the app exists. An attacker who obtains such a grant holds durable access that no credential reset touches, which is why enumerating and pruning OAuth grants belongs in the same review as configuration drift.

Shadow SaaS is the other half. Applications adopted by a team without procurement or IT are invisible to controls nobody knew to apply, and they frequently hold real customer data. Discovering them is the precondition for governing them at all.

How Vijilan covers this
See Managed SaaS Security

Common questions

What does SSPM stand for?

SSPM stands for SaaS Security Posture Management. It refers to continuously monitoring the security configuration of SaaS applications such as Microsoft 365, Google Workspace, Salesforce, Slack and GitHub, and flagging drift away from a known-good baseline.

What is the difference between SSPM and CASB?

A CASB sits in the path of traffic to SaaS applications and governs it, enforcing policy on access and data movement as it happens. SSPM connects to the applications through their APIs and inspects how they are configured. CASB controls the flow, SSPM inspects the settings, and most organizations eventually want both.

Why are OAuth grants a security risk?

Because they create access that survives the controls people trust. A user can authorise a third-party app to read their mail or files without an administrator approving it, and that authorisation keeps working after a password change or a device wipe. Unless grants are inventoried and reviewed, they accumulate as unmonitored standing access to company data.

Glossary

SSPM is one signal.
We watch the rest.

Vijilan runs a 24/7 SOC across endpoint, identity, cloud, network, SaaS and mobile, and acts on what it finds rather than forwarding an alert.