Third-party access to organisational data.
WHAT THE RISK IS
Applications granted access to mail, files and calendars can read everything the user can.
HOW ACCESS IS GRANTED
A user consenting, or an administrator authorising.
WHAT THE PROBLEM IS
Users consent without understanding what they are granting.
WHAT TO CONFIGURE
Restriction of which applications users may authorise An allowlist of approved applications Blocking of unverified applications
WHY BLOCKING UNVERIFIED APPLICATIONS MATTERS
Unverified applications requesting sensitive access are a known attack route.
WHAT TO REVIEW
Which applications have been authorised What scopes each holds How many users granted access
WHAT TO LOOK FOR
Applications nobody can account for Applications with very broad scopes Applications granted access by many users at once
WHY THAT LAST ONE
It may indicate a campaign targeting your organisation.
WHAT TO DO ABOUT A SUSPICIOUS APPLICATION
Revoke its access across the organisation, and investigate what it reached.
WHAT TO ESTABLISH
A process for approving applications.
WHAT TO COMMUNICATE
Why the restriction exists.