SECURITY · APP & DATA EXPOSURE

See every third-party app that can already reach your Microsoft 365 email, files, and calendars, ranked by risk.

A fixed-fee assessment that surfaces every OAuth application and its Microsoft Graph permissions to mail, files, and calendars, ranks the consent risk, and tells you what to revoke.

Fixed priceLedger you keepRead-onlyRanked

The deliverable

OAuth Application Risk Ledger, on your desk

A representative deliverable. Yours is built on your own environment, with names and figures redacted here.

This is for you if

Built for the Owner, IT Director, or CISO.

  • You cannot list which third-party apps can read your email, files, and calendars today.
  • If staff can approve apps themselves, one convincing fake only has to be clicked once.
  • You need a clear revoke-or-keep call, not a raw export.

What you receive

OAuth Application Risk Ledger

Every app, what it is allowed to reach once it is in, a risk rank, and a revoke or keep decision.

High-risk shortlist

The consents to revoke first, with the impact noted.

Consent governance recommendations

How to stop risky consent from happening again.

Typical timeline

4-6 days

Included

  • Enterprise app and consent inventory
  • What each app can reach, ranked by risk
  • Revoke or keep decisions
  • Consent governance recommendations

Assumptions

  • One Microsoft Entra ID tenant

Not included

  • App removal without explicit approval
  • Consent policy deployment

Scoped separately here: Fix & improve.

Required access

  • Read-only Entra ID enterprise apps access
  • A 30-minute kickoff with security or IT

Engagement complete when

The engagement is complete when the OAuth risk ledger and high-risk shortlist are delivered and walked through.

Know which apps to revoke first, and what breaks when you do.

One fixed fee, agreed in writing before any access is granted. The timeline above is the whole engagement, and what you keep is documentation your team can act on. One senior engineer scopes and delivers it.

The fee depends on what is actually in your environment rather than your headcount. The scope-fit check tells you where you land →