Why should you review applications connected to business accounts?

An authorized application can retain access even if the user changes their password. The company needs to know which apps access Microsoft 365 or Google Workspace, what permissions they received, who approved them, and whether they are still needed. Broad or unknown authorizations should be investigated before revoking so as not to disrupt a legitimate integration.

Risks to review

  • Older apps that can still read mail or files.
  • Misleading consents obtained through phishing.
  • Administrative permissions granted to an ownerless integration.
  • Revoke a critical application without knowing the process that depends on it.

Safe recommendations

  1. Maintain an inventory of applications, owners, purpose and permissions granted.
  2. Review applications with domain-wide access or high-impact data first.
  3. Confirm with the responsible area if each integration is still necessary.
  4. Restrict user consent and establish an approval process.
  5. Check activity and sessions when an unknown application appears.
  6. Document and test the revocation before removing an integration from production.

When to seek specialized help

  • An unknown application appears with mail or file permissions.
  • There is no inventory of approved integrations.
  • Suspected consent phishing or token theft.

Reference sources

These public sources provide general good-practice guidance. They do not replace an assessment of your environment.