Applications may also have access to your company’s Microsoft 365 data. Here is how to find out what an application is allowed to do, why it is needed and whether its permissions are still justified.
A sales tool, booking service or backup service may need access to company emails, calendars or files. That access may be necessary for the service to work. But recognising an application’s name does not tell you what data it is allowed to handle.
Your IT team may not be familiar with every tool used across the company. IT can check the permissions, while the team using the application knows why it is needed. That makes the review a shared task.
Imagine a company whose sales team has tried a tool to help manage email. At the start of the trial, the application was granted permission to read a user’s emails. The team later chose another service, but nobody reviewed the old tool’s permissions.
Finding the application in the company’s environment does not, on its own, mean that it has been misused. What matters is finding out who introduced it, what permissions it was granted and whether anyone still uses it. The tool may serve another purpose that IT is not aware of.
The person responsible in sales confirms that the old service is no longer needed. IT checks the associated connections and agrees on removing the permissions. The team also makes sure the data it needs is available and its workflows function in the new service.
The aim of the review is to establish whether the application’s permissions match how it is currently used.
There are two main ways an application can access Microsoft 365 data:
The same permission name can mean different levels of access in these two scenarios. In Microsoft’s example, the delegated Files.Read.All permission allows an application to read files that the user can access. As an application permission, it allows the application to read all files in the organisation through Microsoft Graph. Always check the permission type as well as its name. Read more in Microsoft’s guide to permissions and consent.
Administrator approval alone does not tell you the permission type. An administrator can also approve delegated permissions for an application that acts on a user’s behalf. The permissions an application has and the person who approved them are separate matters. Microsoft explains the distinction in its guide to user and admin consent.
Start with an application whose trial has ended or whose purpose is unclear. Find out who provides the service, who uses it and who is responsible for its use in your company. Ask what the application does and what would be affected if people stopped using it.
Keep a brief record of the answers. Even one sentence helps: “The sales team uses the service to book meetings, and the sales manager is responsible for its use.”
In the Microsoft Entra admin centre, go to Entra ID → Enterprise apps → All applications. Select the application and open Permissions. Review both tabs: Admin consent and User consent. Menu names may vary with the language of the interface.
Check each permission’s description and type: can the application read, change or send data, and which service’s data does the permission cover? The person carrying out the review needs an appropriate administrative role. Microsoft’s guide to reviewing application permissions describes the required roles and views.
Discuss three questions with the person responsible for the application:
If a permission seems broader than the application’s purpose requires, ask the service provider to explain why it is needed and find out whether access can be restricted. Microsoft recommends assessing both the publisher’s trustworthiness and the need for the requested permissions before approving them. See Microsoft’s guidance on evaluating application consent requests.
Permission to read emails is not proof that the application has read them. The permissions list shows what access is allowed. Investigate what the application has actually done separately, using the usage data and logs available to you.
Microsoft distinguishes between granted permissions, permission usage and the amount of data handled in the Defender for Cloud Apps application inventory. Do not treat missing usage data as proof that an application is not being used.
If a permission is unnecessary, agree on its removal with the person responsible for the application. If the application is still in use, establish the impact of restricting its permissions before making the change. Do not remove an unfamiliar application based on its name alone.
IT makes the change to the correct application and checks with its users that the functions they need still work. Permissions granted through consent are not the only way an application can gain access to data. Access can also come from authorisations within individual services. Microsoft explains these considerations in its guide to reviewing and revoking permissions.
Vahti’s interactive demo lets you explore findings related to applications. IT and the person responsible for using the application can assess a finding together: what does it mean, and what should they investigate next?
A finding can be the starting point for a review. Deciding whether an application is needed still requires an understanding of how the company uses it. An application finding in Vahti is not, on its own, proof of data misuse. It does not replace a separate assessment of the permissions granted and how they have actually been used.
Management should make sure each company tool has a named person responsible for it. IT checks permissions and makes changes. The team using the tool explains what it needs from the application. It is also worth reviewing permissions when switching services or when the person responsible for an application leaves the company.
Start with one application. Record its purpose, the person responsible for it, its key permissions and the agreed next step. Use the same checklist when introducing the next tool.
Explore Vahti’s interactive demo to see application findings alongside user risks, file sharing and email rules. Find out more on the Vahti product page.