Supporting technical capability

See which third-party apps can already reach your Microsoft 365 email, files, and calendars, ranked by risk.

List the registered applications and their permissions to email, files and calendars. Rank the access risks and recommend which permissions to retain, change or revoke.

Engagement context

Where this capability applies.

  • You cannot list which third-party apps can read your email, files, and calendars today.
  • If staff can approve apps themselves, one convincing fake only has to be clicked once.
  • You need a clear revoke-or-keep call, not a raw export.

The agreed outputs

What the engagement provides.

Application Consent Risk Review

Each application and consent registered in the tenant, what it is allowed to reach once it is in, a risk rank, and a revoke or keep decision.

High-risk shortlist

The consents to revoke first, with the impact noted.

Consent governance recommendations

How to stop risky consent from happening again.

Worked example

Application Consent Risk Review

An illustration of the record an engagement can produce. Names and figures are constructed for this example.

Illustrative content. The engagement record is developed from the client’s own environment and agreed scope.

Commercial & delivery basis

The scope and conditions of the work.

Delivery window

4-6 days

How engagements are scoped
Included scope
  • Enterprise app and consent inventory
  • What each app can reach, ranked by risk
  • Revoke or keep decisions
  • Consent governance recommendations
Scope assumptions
  • One Microsoft Entra ID tenant
Exclusions
  • App removal without explicit approval
  • Consent policy deployment
Required access
  • Read-only Entra ID enterprise apps access
  • A 30-minute kickoff with security or IT

Acceptance

The agreed completion standard.

The engagement is complete when the OAuth risk ledger and high-risk shortlist are delivered and walked through.

Discuss the work

Tell us what you need to change.

Share the systems involved, why the change is needed and your deadline. We clarify the work, responsibilities and information needed for a proposal.

Request an Architecture Briefing