CIO Brief: Who Approved That App? Governing OAuth Permissions
Retrospective: this article looks back at events from March 2018, written in 2026 with the benefit of hindsight.
The short version: Cambridge Analytica obtained data on tens of millions of Facebook users through an app most of them never used. The same mechanism — apps requesting access to your data — exists in Microsoft 365, and attackers use it.
Why app permissions are a governance issue
When an employee clicks "Accept" on an app permission screen, they may give that app ongoing access to their email, files or calendar. Some permissions reach other people's data too. Many organizations have hundreds of such apps connected, and few have reviewed them.
The business impact
- Data exposure to app vendors, legitimate or not.
- Persistent attacker access: malicious apps keep working after password resets and MFA.
- Compliance risk: data shared with unvetted third parties may violate privacy commitments.
Questions to ask your team
- How many third-party apps have access to our Microsoft 365 data?
- Can employees approve apps on their own, and for what level of access?
- Do we review apps that can read everyone's mail or files?
- How do employees request a new app, and how long does it take?
What good looks like
Employees can approve only low-risk apps from verified publishers; anything more goes through a quick admin review; high-access apps are reviewed regularly and removed when unused.
The decision
Ask for a list of the apps with the broadest access to company data, and a recommendation on user consent settings. It is usually a single settings change with outsized benefit.
- Cambridge Analytica (Mar 2018): What App Permissions Mean for Your Microsoft 365 Tenant Incident Teardowns
- How to Lock Down User Consent to Third-Party Apps in Entra ID How-To & Hardening
- Detecting OAuth App Over-Permission: Defender XDR and Sentinel Hunting Queries Detection & Response