Shadow IT & OAuth App Governance
9 checks · 2 sub-categories
Every app a staff member connects to Microsoft 365 keeps its permissions until someone revokes them — often the right to read mail, files and contacts, indefinitely, long after the person stopped using it. Attackers know this and use consent grants as quiet, password-proof persistence.
Application consent
User consent to third-party apps restricted
Whether staff can grant an unknown app access to their mailbox on their own, or whether an administrator must approve it.
- Essential Eight — Application control
- CIS 2.7
Admin consent request workflow enabled
The right pattern is 'ask an admin', not a hard block that pushes staff to personal accounts instead.
Full inventory of consented applications
Every connected app, who consented, when, and exactly which permission scopes it holds.
High-risk permission scopes flagged
Mail.ReadWrite, Mail.Send, Files.ReadWrite.All and directory-wide permissions are called out individually for review.
- Privacy Act — third-party disclosure
Dormant and orphaned app registrations
Apps and service principals with live credentials but no recent use, including ones tied to former staff or former IT providers.
Shadow IT discovery
Unsanctioned SaaS in use across the business
Identifies the file-sharing, AI, note-taking and CRM tools staff have signed up for with work accounts outside the approved stack.
Business data flowing to unapproved services
Where company documents or customer data are being stored or processed outside your tenant.
- Privacy Act — offshore and third-party disclosure
Duplicate and overlapping tooling
Often produces immediate savings — three teams paying for three versions of the same product.
Browser extensions with tenant access
Extensions granted permission to read mail or documents through the browser session.
Want to know where you actually stand?
Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.