Which applications can act on tenant data, and who approved that authority?
Review the non-human access paths that remain outside a simple user-and-MFA checklist.
Begin with the business decision and the affected population. A targeted workload review may be sufficient; an interconnected tenant assessment may be more useful where the same identity, device or data dependency affects several services.
Evidence we agree to examine
- Enterprise applications, app registrations, service principals and current owners
- Delegated versus application permissions, consent grants and the business purpose
- Credential lifecycle, unused integrations and privileged access dependencies
- User consent settings, administrator approval workflow and review records
Why context changes the conclusion
An approved integration can retain permissions long after its sponsor leaves. A familiar app name or publisher status does not establish a current need for every granted permission.
Treat this as an assessment question, not a finding about your organisation. During an engagement, a conclusion must identify the dated evidence, the sampled population and any exceptions that could not be corroborated.
The output your team can use
An application access register with owner decisions, reduction opportunities and validation steps.
Each action should identify its accountable owner, licence or business dependency, proposed rollout safeguards and the record that will demonstrate successful closure. A policy screenshot alone is not enough when the finding concerns coverage or sustained operation.
Access and boundaries
No application is disabled or secret rotated as part of a read-only review. Existing consent requires contextual review before changes.
We agree evidence access before work begins. Your team can lead supervised sessions and provide approved, minimised exports. The assessment does not require you to send passwords, grant access through this website or permit production changes. See access and data handling.
Prepare your audit request
Use the Microsoft 365 Audit Planner for a licence-aware starting scope, or the detailed scoping assistant. Review the brief and send it with your enquiry. You can attach your NDA or RFP in the contact form.
Sources & further reading
Reviewed 6 October 2026. Product names, licence entitlements and guidance can change. Confirm applicability to your tenant and agreed assessment date.

