Skip to content

Application security

Audit third-party OAuth apps in Google Workspace and Microsoft 365

Inventory connected apps and consent, rank grants by scope, and verify keep, restrict, or revoke decisions in the source.

What to take away

An app connected with OAuth can reach work data through permissions that are easy to overlook during an access review. Use the native Google Workspace and Microsoft Entra inventories, record each grant’s source and scope, then verify every change. Do not infer that a token still works from an old consent record: for example, Google suspension resets the affected user’s OAuth tokens, while tenant-wide consent and other users’ grants need their own review.

1. Separate sign-in, user grants, and tenant consent

SSO assignment, a user’s OAuth grant, and organization-wide admin consent are different objects. Disabling an account can stop sign-in and invalidate tokens without removing the application from the organization’s consent inventory. Google says suspending a compromised user resets sign-in cookies and OAuth tokens; it is therefore wrong to assume that this user’s old Google token keeps working. Review remaining app policy and other grants separately.

Browser extensions form a fourth surface. Their local permissions are managed in the browser or device fleet, not by deleting an Entra consent record. Record each surface rather than calling every application sighting a verified account.

References: Google Workspace — Control which apps access data · Google Workspace — Secure a compromised account · Microsoft Entra — Review and revoke app permissions

2. Build a dated inventory from native sources

In Google Admin, open Security → Access and data control → API controls → Manage App Access. Review Accessed apps and Configured apps, then export the list if useful. Record the OAuth client ID, users, requested services and scopes, verification status, and OU-specific Trusted, Limited, Specific Google data, or Blocked setting. Google says app details typically appear 24–48 hours after authorization and the accessed list can lag token changes by 48 hours.

In Microsoft Entra, open Enterprise apps → All applications → Permissions. Review Admin consent and User consent separately, along with delegated versus application permissions. The portal can revoke admin-granted permissions; user consent is shown there but must be revoked through Microsoft Graph or PowerShell. Include managed-browser extensions in a separate row when they can access sensitive sites or data.

2. Build a dated inventory from native sources
RecordWhy it matters
App and client IDIdentifies the grant beyond a display name
Source and consent typeDistinguishes user, tenant, and browser evidence
Users and scopesShows reach and allowed data or actions
Owner and snapshot dateMakes the decision and freshness reviewable

References: Google Workspace — Control which apps access data · Microsoft Entra — Review and revoke app permissions

3. Prioritize what a grant can do

Start with mail read or send, broad file access, directory changes, offline access, and tenant-wide consent. A familiar brand or Google verification badge does not establish an approved business use. Conversely, basic sign-in scopes may need less urgent review than a lesser-known app with write access to files.

For each candidate, ask who owns the use, whether the scopes are still needed, how many users are covered, and whether a narrower permission or assignment would work. Keep uncertain scope and stale observations visible instead of silently treating them as safe.

4. Keep, restrict, or revoke

Keep a grant with a current owner, justified scopes, and a review date. Restrict an over-scoped but necessary app: Google supports Limited or Specific Google data settings and OU-specific policy; Entra supports removing unnecessary admin consent and tightening consent or assignment policy. Check the impact on legitimate users before applying broad restrictions.

Revoke a grant with no owner or current need. In Google, use the relevant API-controls or user-token action and confirm which users or OUs it affects. In Entra, revoke admin consent in the enterprise app; use Graph or PowerShell for a user-consent grant. Remove or block unwanted browser extensions through browser management. A decision in a spreadsheet is not evidence that the source changed.

References: Google Workspace — Control which apps access data · Microsoft Entra — Review and revoke app permissions

5. Verify the source and repeat the review

Reopen the same admin view after a change, confirm the client ID and scope, and spot-check affected access without exposing customer data. Existing Microsoft access tokens can remain valid until expiry after a delegated grant is deleted, while console lists can lag. Record what you verified and when; leave partial changes open.

Review new accessed apps monthly, revisit broad consent and extension allowlists quarterly, and add a grant check to offboarding. Account disablement is an important control, but the wider app inventory and tenant-wide settings still need an owner.

References: Google Workspace — Control which apps access data · Microsoft Graph — Delete a delegated permission grant

How Elba supports the audit

Third-Party Apps brings supported connected-account and OAuth evidence together with email and Browser Security observations in one application inventory, preserving the source of each signal. Browser use or an installed extension is an observation, not proof of a connector-confirmed grant.

Administrators can assign an application owner and usage policy, distribute eligible findings, and use source-supported remediation. Direct permission removal depends on the integration and the specific grant; Google Workspace user-grant actions require the separate Google security connection when enabled. Verify the live connection and source result before marking an audit row complete.

References: Elba — Third-Party Apps

OAuth app audit checklist

0 of 7 checks complete

Your checks stay on this page and reset when you reload it.

Common questions

Does suspending a Google user leave their OAuth tokens active?

Google says suspension resets that user’s sign-in cookies and OAuth tokens. Still review the application’s policy, tenant-wide settings, and grants for other users; do not equate an old inventory row with a working token.

Can I revoke Entra user consent in the portal?

The User consent tab shows those grants, but Microsoft says revocation there requires Graph or PowerShell. Admin consent can be revoked in the enterprise-app portal.

Does an app seen in the browser have a confirmed OAuth grant?

No. Browser use and extension installation are observations. Confirm account or grant access with a connected source before taking grant-level action.

Sources & further reading

Primary documentation used to review this guide. Product settings and edition requirements can change; check the linked documentation before making changes.

Put it into practice

Shadow AI securityUser access review checklistApplication discovery and access reviews

From review to remediation

See connected app evidence in one place

Explore how Elba separates verified grants from observed use and supports owner-led app reviews.

Request a demo