← Microsoft 365 audit scope

Shadow IT & OAuth App Governance

9 checks · 2 sub-categories

Every app a staff member connects to Microsoft 365 keeps its permissions until someone revokes them — often the right to read mail, files and contacts, indefinitely, long after the person stopped using it. Attackers know this and use consent grants as quiet, password-proof persistence.

Application consent

  • User consent to third-party apps restricted

    Whether staff can grant an unknown app access to their mailbox on their own, or whether an administrator must approve it.

    • Essential Eight — Application control
    • CIS 2.7
  • Admin consent request workflow enabled

    The right pattern is 'ask an admin', not a hard block that pushes staff to personal accounts instead.

  • Full inventory of consented applications

    Every connected app, who consented, when, and exactly which permission scopes it holds.

  • High-risk permission scopes flagged

    Mail.ReadWrite, Mail.Send, Files.ReadWrite.All and directory-wide permissions are called out individually for review.

    • Privacy Act — third-party disclosure
  • Dormant and orphaned app registrations

    Apps and service principals with live credentials but no recent use, including ones tied to former staff or former IT providers.

Shadow IT discovery

  • Unsanctioned SaaS in use across the business

    Identifies the file-sharing, AI, note-taking and CRM tools staff have signed up for with work accounts outside the approved stack.

  • Business data flowing to unapproved services

    Where company documents or customer data are being stored or processed outside your tenant.

    • Privacy Act — offshore and third-party disclosure
  • Duplicate and overlapping tooling

    Often produces immediate savings — three teams paying for three versions of the same product.

  • Browser extensions with tenant access

    Extensions granted permission to read mail or documents through the browser session.

Want to know where you actually stand?

Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.