Microsoft 365How-To & HardeningRetrospectives

How to Review Third-Party Apps With Access to Exchange Online

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2021, written in 2026 with the benefit of hindsight.

Third-party applications connected to Exchange Online can read, send or manage mail across your organization. Here is how to review them.

Step 1: List apps with Exchange or mail permissions

In the Entra admin center under Enterprise applications, filter and review apps with:

  • Microsoft Graph application permissions: Mail.Read, Mail.ReadWrite, Mail.Send, MailboxSettings.ReadWrite.
  • Exchange permissions: full_access_as_app, EWS.AccessAsUser.All.
  • Delegated permissions granted tenant-wide (admin consent) for mail.

Defender for Cloud Apps app governance provides a consolidated view of data accessed by each app.

Step 2: Identify the owner and purpose

For each app: which vendor, which business owner, what it needs mail access for, and whether it's still used.

Step 3: Check scope

Does the app need access to every mailbox? Most don't. Restrict with RBAC for Applications in Exchange Online (the successor to application access policies) to specific mailboxes or groups.

Step 4: Check authentication

  • Is it a multi-tenant vendor app, or an app registration in your tenant with secrets you manage?
  • For apps in your tenant: prefer certificates over secrets, and rotate them.

Step 5: Remove what isn't needed

Disable and remove apps that are unused or unowned, after confirming with stakeholders.

Step 6: Monitor

  • Alert on new apps granted mail permissions.
  • Review MailItemsAccessed events (Microsoft Purview Audit) for apps accessing many mailboxes.

Verify

Quarterly review, with a short list of approved mail-access apps maintained by IT.

review exchange online app accessMimecast certificate2021

More on this story