For the engagement owner. Review the applications that can access your tenant independently of an ordinary interactive sign-in.
Treat applications as access-bearing identities
Third-party services and internal automation can receive permissions to work with Microsoft 365 data. A user-focused review can miss this boundary. Inventory enterprise applications, owners, consent grants and relevant credentials. Separate delegated access, which acts in a user context, from application permissions used without a signed-in user. Neither category should be assessed solely from a friendly application display name.
Read diagram text
- Delegated
- Access in a user context.
- Application
- Access without an interactive user.
- Ownership
- A business purpose and accountable owner.
Establish a business owner and purpose
Ask why each selected application exists, who requested it and who owns its lifecycle. Compare the declared purpose with the granted permission scope. An integration intended to support a limited business process may have accumulated broader access over time. Evidence of a vendor relationship is not itself approval for every permission. Record uncertainty and ask the application owner to explain dependencies before recommending removal.

Review consent and change control
Examine the tenant’s user-consent configuration and administrative approval process. Look for how requested permissions are reviewed, how publishers are assessed and how changes are detected. A verified publisher can be a useful signal, but it does not establish that the requested access is appropriate for your organisation. Microsoft’s consent-phishing guidance is a useful reference for distinguishing business approval from a user being persuaded to authorise an app.
Read diagram text
- Purpose
- What does the integration need?
- Grant
- What access was actually approved?
- Difference
- What requires explanation or reduction?
Consider credentials and stale integrations
Review selected certificate or secret expiry, ownership and rotation arrangements without collecting the secret values. Identify inactive or abandoned integrations for owner review. Last-used information can be incomplete, so avoid deleting a production dependency based on one timestamp. Agree how the team will confirm use, assess impact and reverse a change if necessary. The audit should make the decision reviewable rather than automate destructive cleanup.
Read diagram text
- Approval
- Assess the request and change history.
- Credential
- Record owner and expiry without secrets.
- Retirement
- Verify dependencies before removal.
Do not turn a concern into an unsupported incident claim
An unexplained permission deserves investigation, but it does not prove malicious use. Record what the configuration shows and what activity evidence is available. If there are credible signs of compromise, move to an incident-response process with appropriate preservation and containment. A routine audit must not overwrite evidence or present a speculative attack narrative as an observed event.
Plan the operational handover
Include application retirement in supplier and employee transitions. An integration may survive its original sponsor; make its continuing purpose, credential owner and review schedule visible to the team receiving responsibility.
Related Atlant Security guidance: establishing evidence coverage and separating monitoring and incident response. Use these to connect the review with the evidence and responsibilities needed after it.
Scope the application review
The OAuth and application permissions audit covers these questions as a distinct workstream. Include approximate application counts, the existence of internal automation and any known integrations in the planner. Share detailed inventories only after agreeing the handling channel. For a wider environment, our cybersecurity audit service can also examine the process that governs application access across platforms.
Read diagram text
- Observe
- Record the actual configuration.
- Correlate
- Review available activity evidence.
- Escalate
- Use incident response when warranted.
Sources & further reading
Reviewed 6 October 2026. Product names, licence entitlements and guidance can change. Confirm applicability to your tenant and agreed assessment date.
This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client assessments.
Published by Atlant Security. Sources, editorial policy and corrections.
