How to Review Third-Party Apps With Access to Exchange Online
Retrospective: this article looks back at events from January 2021, written in 2026 with the benefit of hindsight.
Third-party applications connected to Exchange Online can read, send or manage mail across your organization. Here is how to review them.
Step 1: List apps with Exchange or mail permissions
In the Entra admin center under Enterprise applications, filter and review apps with:
- Microsoft Graph application permissions:
Mail.Read,Mail.ReadWrite,Mail.Send,MailboxSettings.ReadWrite. - Exchange permissions:
full_access_as_app,EWS.AccessAsUser.All. - Delegated permissions granted tenant-wide (admin consent) for mail.
Defender for Cloud Apps app governance provides a consolidated view of data accessed by each app.
Step 2: Identify the owner and purpose
For each app: which vendor, which business owner, what it needs mail access for, and whether it's still used.
Step 3: Check scope
Does the app need access to every mailbox? Most don't. Restrict with RBAC for Applications in Exchange Online (the successor to application access policies) to specific mailboxes or groups.
Step 4: Check authentication
- Is it a multi-tenant vendor app, or an app registration in your tenant with secrets you manage?
- For apps in your tenant: prefer certificates over secrets, and rotate them.
Step 5: Remove what isn't needed
Disable and remove apps that are unused or unowned, after confirming with stakeholders.
Step 6: Monitor
- Alert on new apps granted mail permissions.
- Review MailItemsAccessed events (Microsoft Purview Audit) for apps accessing many mailboxes.
Verify
Quarterly review, with a short list of approved mail-access apps maintained by IT.