Independent Microsoft 365 security assessment.Atlant Security
365/AuditBY ATLANT SECURITY
Build your scope Audit brief builder

APPLICATION ACCESS

OAuth app permissions: the access a user-MFA review can miss

Inventory enterprise applications, delegated permissions, application permissions and consent ownership.

Discuss your requirements
Layered glass partitions in an illustrative corporate atrium

For the engagement owner. Review the applications that can access your tenant independently of an ordinary interactive sign-in.

Treat applications as access-bearing identities

Third-party services and internal automation can receive permissions to work with Microsoft 365 data. A user-focused review can miss this boundary. Inventory enterprise applications, owners, consent grants and relevant credentials. Separate delegated access, which acts in a user context, from application permissions used without a signed-in user. Neither category should be assessed solely from a friendly application display name.

Separate access types. Delegated: Access in a user context.; Application: Access without an interactive user.; Ownership: A business purpose and accountable owner.
Working model 01Separate access typesIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Delegated
Access in a user context.
Application
Access without an interactive user.
Ownership
A business purpose and accountable owner.

Establish a business owner and purpose

Ask why each selected application exists, who requested it and who owns its lifecycle. Compare the declared purpose with the granted permission scope. An integration intended to support a limited business process may have accumulated broader access over time. Evidence of a vendor relationship is not itself approval for every permission. Record uncertainty and ask the application owner to explain dependencies before recommending removal.

Architectural boundaries illustrated by smoked glass and stone
Operational perspectiveMake access boundaries explicit.Generated illustrative setting; not a client location.

Review consent and change control

Examine the tenant’s user-consent configuration and administrative approval process. Look for how requested permissions are reviewed, how publishers are assessed and how changes are detected. A verified publisher can be a useful signal, but it does not establish that the requested access is appropriate for your organisation. Microsoft’s consent-phishing guidance is a useful reference for distinguishing business approval from a user being persuaded to authorise an app.

Review the permission. Purpose: What does the integration need?; Grant: What access was actually approved?; Difference: What requires explanation or reduction?
Working model 02Review the permissionIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Purpose
What does the integration need?
Grant
What access was actually approved?
Difference
What requires explanation or reduction?

Consider credentials and stale integrations

Review selected certificate or secret expiry, ownership and rotation arrangements without collecting the secret values. Identify inactive or abandoned integrations for owner review. Last-used information can be incomplete, so avoid deleting a production dependency based on one timestamp. Agree how the team will confirm use, assess impact and reverse a change if necessary. The audit should make the decision reviewable rather than automate destructive cleanup.

Manage lifecycle. Approval: Assess the request and change history.; Credential: Record owner and expiry without secrets.; Retirement: Verify dependencies before removal.
Working model 03Manage lifecycleIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Approval
Assess the request and change history.
Credential
Record owner and expiry without secrets.
Retirement
Verify dependencies before removal.

Do not turn a concern into an unsupported incident claim

An unexplained permission deserves investigation, but it does not prove malicious use. Record what the configuration shows and what activity evidence is available. If there are credible signs of compromise, move to an incident-response process with appropriate preservation and containment. A routine audit must not overwrite evidence or present a speculative attack narrative as an observed event.

Plan the operational handover

Include application retirement in supplier and employee transitions. An integration may survive its original sponsor; make its continuing purpose, credential owner and review schedule visible to the team receiving responsibility.

Related Atlant Security guidance: establishing evidence coverage and separating monitoring and incident response. Use these to connect the review with the evidence and responsibilities needed after it.

Scope the application review

The OAuth and application permissions audit covers these questions as a distinct workstream. Include approximate application counts, the existence of internal automation and any known integrations in the planner. Share detailed inventories only after agreeing the handling channel. For a wider environment, our cybersecurity audit service can also examine the process that governs application access across platforms.

Respond proportionately. Observe: Record the actual configuration.; Correlate: Review available activity evidence.; Escalate: Use incident response when warranted.
Working model 04Respond proportionatelyIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Observe
Record the actual configuration.
Correlate
Review available activity evidence.
Escalate
Use incident response when warranted.

Sources & further reading

Reviewed 6 October 2026. Product names, licence entitlements and guidance can change. Confirm applicability to your tenant and agreed assessment date.

This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client assessments.

Published by Atlant Security. Sources, editorial policy and corrections.

PUT THE GUIDANCE TO WORK

Choose your next step.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your audit objectives, control boundaries and evidence period. A useful starting point for your assessment.

Discuss your requirements