SecureMyEmail logoSecureMyEmail

Microsoft 365 security guide

Review third-party apps in Microsoft 365

A practical, step-by-step guide for Australian businesses. Find obsolete, excessive or potentially malicious access to Microsoft 365 mailboxes, files, Teams and directory data.

Reviewing third-party app permissions connected to Microsoft 365 services

Recommended method: review, classify and restrict third-party app access every three months

Third-party applications can retain ongoing access to Microsoft 365 mailboxes, OneDrive, SharePoint, Teams and organisational data. Regularly reviewing these applications helps identify obsolete, excessive or potentially malicious access.

Before you begin

You will generally need one of these Microsoft Entra roles:

  • Cloud Application Administrator, Application Administrator, or Global Administrator role for certain consent-policy changes.
  • Use a separate administrative account and record the existing configuration before making changes.
1

Open the Microsoft Entra admin centre

  • Go to the Microsoft Entra admin centre.
  • Sign in with an authorised administrator account.
  • Select Entra ID.
  • Go to Enterprise apps.
  • Select All applications.

This list includes third-party applications, Microsoft applications, service accounts and integrations added to the tenant.

2

Identify applications requiring review

Review applications that are:

  • Unrecognised or no longer used.
  • From an unknown or unverified publisher.
  • Authorised by former employees.
  • Used by very few people.
  • Duplicated or replaced by another product.
  • Not supported by a current supplier.
  • Requesting access beyond their business purpose.

Do not assume an unfamiliar application is malicious. It might support backup, email security, accounting, CRM, document signing, monitoring or another managed service.

3

Review each application

Select an application and inspect the following areas.

Properties

Record the application name, application ID, publisher and verification status, whether users can sign in, whether user assignment is required, and who owns or manages the application.

Users and groups

  • Select Users and groups.
  • Check which users and groups are assigned.
  • Confirm whether those people still require the application.

Permissions

  • Select Permissions.
  • Review the Admin consent tab.
  • Review the User consent tab, if displayed.
  • Select individual permissions to see more information.

Be aware that the Users and groups page may not show every user who has individually consented to an application.

4

Look for high-risk access

Pay particular attention to permissions that allow an application to:

  • Read, modify or delete email.
  • Send email as a user.
  • Access every mailbox.
  • Read or modify OneDrive files.
  • Access all SharePoint sites.
  • Maintain access while the user is offline.
  • Read or modify users, groups or directory information.
  • Access calendars, contacts, chats or Teams content.
  • Operate without a signed-in user.

Examples that deserve careful examination include:

  • Mail.Read
  • Mail.ReadWrite
  • Mail.Send
  • Files.Read.All
  • Files.ReadWrite.All
  • Sites.Read.All
  • Sites.ReadWrite.All
  • Sites.FullControl.All
  • Directory.ReadWrite.All
  • offline_access
  • Exchange application permissions such as full_access_as_app

A permission is not automatically unsafe merely because it is powerful. Backup, migration, security and compliance products may legitimately require broad access.

5

Confirm the business requirement

Before changing an application, identify:

  • The application owner.
  • The supplier or publisher.
  • The users who rely on it.
  • Its business purpose.
  • The exact permissions it needs.
  • Whether a less-privileged integration is available.
  • Whether removing access would affect backups, email delivery, workflows or sign-in.

Classify each application as:

ClassificationMeaning
ApprovedRecognised, supported and appropriately permissioned.
Reduce accessRequired, but permissions or user assignments are excessive.
Disable and investigateUnrecognised, suspicious or awaiting confirmation.
RemoveConfirmed as obsolete or unauthorised.

Maintain an application register containing the owner, purpose, permissions, approval decision and next review date.

6

Remove unnecessary user assignments

  • Open the application.
  • Select Users and groups.
  • Select an unnecessary user or group.
  • Select Remove.
  • Confirm the change.
  • Test the application with an authorised user.

Removing an assignment is not always the same as revoking OAuth consent. Review the application’s Permissions page as well.

7

Revoke unnecessary admin-granted permissions

  • Open the application.
  • Select Permissions.
  • Open the Admin consent tab.
  • Locate the unnecessary permission.
  • Select the three-dot menu beside it.
  • Select Revoke permission.
  • Confirm the change.
  • Test all related business functions.

Microsoft notes that permissions shown under User consent cannot currently be revoked through that portal page. Those grants may require Microsoft Graph or PowerShell.

8

Disable a suspicious application

  • Open Entra ID → Enterprise apps → All applications.
  • Select the application.
  • Select Properties.
  • Change Enabled for users to sign-in? to No.
  • Select Save.
  • Investigate its users, permissions, sign-in activity and owner.

Disabling the application prevents new tokens and sign-ins while retaining its configuration for investigation.

9

Delete an obsolete application

  • Open the application.
  • Select Properties.
  • Select Delete.
  • Select Yes to confirm.
  • Document the deletion and monitor affected systems.

Microsoft states that a deleted enterprise application normally remains recoverable for 30 days before permanent deletion.

10

Restrict future application consent

  • In the Entra admin centre, go to Entra ID.
  • Select Enterprise apps.
  • Open Consent and permissions.
  • Select User consent settings.
  • Set the recommended option: Allow user consent for apps from verified publishers, for selected permissions.
  • Select Save.

For stricter environments, user consent can be disabled entirely, but this can increase administrative workload. Microsoft recommends limiting consent to verified publishers and selected low-risk permissions.

11

Enable the admin consent request workflow

  • Go to Entra ID → Enterprise apps.
  • Select Consent and permissions.
  • Select Admin consent settings.
  • Set Users can request admin consent to apps they are unable to consent to to Yes.
  • Select suitable reviewers.
  • Enable email notifications and expiry reminders.
  • Set an appropriate request expiry period.
  • Select Save.

Microsoft advises that enabling the workflow can take up to one hour.

Recommended review frequency

  • Review all third-party applications at least every three months.
  • Review high-risk application permissions monthly.
  • Review immediately following a security incident.
  • Remove access when an employee leaves or a supplier relationship ends.
  • Require formal approval before granting tenant-wide admin consent.

Warnings

  • Revoking permissions can immediately stop backups, security monitoring, CRM synchronisation, document workflows, email signatures or line-of-business systems.
  • Deleting an enterprise application can break single sign-on and automated integrations.
  • Removing email permissions may interrupt archiving, filtering, migration or backup services.
  • Removing file permissions may interrupt SharePoint, OneDrive or Teams workflows.
  • Changing user-consent settings affects future consent only; it does not remove permissions already granted.
  • Some applications use application permissions and operate without a signed-in user.
  • Do not remove Microsoft-owned applications solely because their names are unfamiliar.
  • If you suspect a malicious OAuth application, disable it promptly, preserve relevant evidence and begin an incident investigation.

Microsoft 365 disclaimer

These instructions provide general security guidance and may not account for your Microsoft 365 licensing, integrations, compliance obligations or business applications. Microsoft can change portal names and menu locations without notice.

Incorrectly revoking permissions or deleting applications may cause service interruptions or data-access failures. Before making changes, document the existing configuration, confirm the business owner, assess dependencies and prepare a rollback plan. If you are uncertain about an application or permission, engage a qualified Microsoft 365 security engineer rather than removing it without investigation.