How to review Microsoft 365 app permissions | Vahti

Written by Teemu Tapper | Sep 17, 2026, 7:47:23 AM

Applications may also have access to your company’s Microsoft 365 data. Here is how to find out what an application is allowed to do, why it is needed and whether its permissions are still justified.

A sales tool, booking service or backup service may need access to company emails, calendars or files. That access may be necessary for the service to work. But recognising an application’s name does not tell you what data it is allowed to handle.

Your IT team may not be familiar with every tool used across the company. IT can check the permissions, while the team using the application knows why it is needed. That makes the review a shared task.

Example: the trial ended, but the application’s permissions remained

Imagine a company whose sales team has tried a tool to help manage email. At the start of the trial, the application was granted permission to read a user’s emails. The team later chose another service, but nobody reviewed the old tool’s permissions.

Finding the application in the company’s environment does not, on its own, mean that it has been misused. What matters is finding out who introduced it, what permissions it was granted and whether anyone still uses it. The tool may serve another purpose that IT is not aware of.

The person responsible in sales confirms that the old service is no longer needed. IT checks the associated connections and agrees on removing the permissions. The team also makes sure the data it needs is available and its workflows function in the new service.

The aim of the review is to establish whether the application’s permissions match how it is currently used.

Does the application act on behalf of a user or independently?

There are two main ways an application can access Microsoft 365 data:

  • An application acting on behalf of a user uses delegated permissions. Its access is limited by both the permissions granted to the application and the user’s own permissions. With delegated permissions, the application cannot access data that the user cannot access.
  • An application acting independently uses application permissions. It can operate without a signed-in user, for example to run backups in the background. The extent of its access depends on the permissions granted to it and any restrictions applied by the relevant service.

The same permission name can mean different levels of access in these two scenarios. In Microsoft’s example, the delegated Files.Read.All permission allows an application to read files that the user can access. As an application permission, it allows the application to read all files in the organisation through Microsoft Graph. Always check the permission type as well as its name. Read more in Microsoft’s guide to permissions and consent.

Administrator approval alone does not tell you the permission type. An administrator can also approve delegated permissions for an application that acts on a user’s behalf. The permissions an application has and the person who approved them are separate matters. Microsoft explains the distinction in its guide to user and admin consent.

How to review one application

1. Identify its purpose and the person responsible for it

Start with an application whose trial has ended or whose purpose is unclear. Find out who provides the service, who uses it and who is responsible for its use in your company. Ask what the application does and what would be affected if people stopped using it.

Keep a brief record of the answers. Even one sentence helps: “The sales team uses the service to book meetings, and the sales manager is responsible for its use.”

2. Check the permissions granted in Microsoft Entra

In the Microsoft Entra admin centre, go to Entra ID → Enterprise apps → All applications. Select the application and open Permissions. Review both tabs: Admin consent and User consent. Menu names may vary with the language of the interface.

Check each permission’s description and type: can the application read, change or send data, and which service’s data does the permission cover? The person carrying out the review needs an appropriate administrative role. Microsoft’s guide to reviewing application permissions describes the required roles and views.

3. Compare the permissions with how the application is used

Discuss three questions with the person responsible for the application:

  • Is the application still needed?
  • What company data does it need to handle?
  • Does it need all its current permissions to do that job?

If a permission seems broader than the application’s purpose requires, ask the service provider to explain why it is needed and find out whether access can be restricted. Microsoft recommends assessing both the publisher’s trustworthiness and the need for the requested permissions before approving them. See Microsoft’s guidance on evaluating application consent requests.

4. Distinguish granted permissions from actual use

Permission to read emails is not proof that the application has read them. The permissions list shows what access is allowed. Investigate what the application has actually done separately, using the usage data and logs available to you.

Microsoft distinguishes between granted permissions, permission usage and the amount of data handled in the Defender for Cloud Apps application inventory. Do not treat missing usage data as proof that an application is not being used.

5. Make the agreed change and check that everything still works

If a permission is unnecessary, agree on its removal with the person responsible for the application. If the application is still in use, establish the impact of restricting its permissions before making the change. Do not remove an unfamiliar application based on its name alone.

IT makes the change to the correct application and checks with its users that the functions they need still work. Permissions granted through consent are not the only way an application can gain access to data. Access can also come from authorisations within individual services. Microsoft explains these considerations in its guide to reviewing and revoking permissions.

How does Vahti help with application reviews?

Vahti’s interactive demo lets you explore findings related to applications. IT and the person responsible for using the application can assess a finding together: what does it mean, and what should they investigate next?

An example from Vahti’s public demo. The applications and findings shown are illustrative.

A finding can be the starting point for a review. Deciding whether an application is needed still requires an understanding of how the company uses it. An application finding in Vahti is not, on its own, proof of data misuse. It does not replace a separate assessment of the permissions granted and how they have actually been used.

Review permissions when a trial ends, too

Management should make sure each company tool has a named person responsible for it. IT checks permissions and makes changes. The team using the tool explains what it needs from the application. It is also worth reviewing permissions when switching services or when the person responsible for an application leaves the company.

Start with one application. Record its purpose, the person responsible for it, its key permissions and the agreed next step. Use the same checklist when introducing the next tool.

Explore Vahti’s interactive demo to see application findings alongside user risks, file sharing and email rules. Find out more on the Vahti product page.