Skip to content

Which external apps have access to our Microsoft 365?

Every 'Sign in with Microsoft' grants scopes to a third party. Sometimes temporary, sometimes forgotten. Time to walk through.

Try this first

  1. 1Entra > Enterprise applications > All applications. All apps where users have ever clicked 'Accept'.
  2. 2Filter by 'Application type: Enterprise applications'. Microsoft's own apps you can ignore. External apps are the interesting ones.
  3. 3Per app: review the permissions. 'Read all mail' or 'Send as user' on an app you do not recognize is a red flag.
  4. 4Apps no one uses anymore: remove via 'Properties > Delete'. First test by setting 'Enabled for users to sign-in' to No and see if anyone shouts.
  5. 5Set admin consent for risky scopes (Entra > Consent and permissions). Then users cannot self-approve mail-read scopes.

When to bring us in

Apps with 'Mail.ReadWrite' or 'full_access_as_app' scopes from an unknown vendor: call us, do not remove yourself. First check whether active data transfer is running before you cut anything off.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.