Skip to main content
Connected Apps: Who Still Has Access to Your Business?
4:17

 

How Forgotten App Permissions Are Leaving Your Microsoft and Google Accounts Wide Open

Think about every app you have ever connected to your Microsoft 365 or Google Workspace account.

A scheduling tool. An e-signature platform. A project management app you used once on a contract two years ago. A tool someone on your team signed in with their work account and never mentioned.

Every one of those connections is still active unless you went back and removed it.

Most businesses never do.

 

What Are Connected Apps and Why Are They a Risk?

Connected apps, also called third-party app integrations, are external tools or platforms that you have granted permission to access your Microsoft 365 or Google Workspace account.

When you connect an app, you are authorizing it to read or modify data in your account. That typically includes your email, your calendar, your contacts, and in many cases your files and documents. The permission is granted through a standard process called OAuth, which allows the app to access your account without needing your actual password.

The problem is that this permission does not expire automatically. Once granted, it remains active indefinitely, even if you stop using the app, forget it exists, or the company behind it changes ownership or gets hacked.

Every connected app that still has active permissions is a potential entry point. If that app is ever compromised, the attacker inherits every permission you originally granted without needing to break into your account directly.

 

Why This Matters

Most business owners and managers have no idea how many connected apps are currently active on their accounts.

When we check, the number is almost always higher than expected. And it routinely includes apps the account holder does not recognize, cannot name, or has not used in years.

For businesses using Microsoft 365 or Google Workspace, a single compromised connected app can give an attacker access to years of email, documents, calendar data, and contacts — all through a legitimate, pre-authorized connection that looks like normal activity.

 

The Real Problem

The risk isn'tt the apps you use every day. It's the ones you've forgotten about.

And because the access comes through a legitimate connection, it often goes undetected for a long time. There is no failed login attempt. No suspicious authentication. The attacker is simply using a door you left open.

 

Cybersecurity Tip: How to Reduce the Risk From Connected Apps

This is one of the most practical security improvements a business can make. It requires no technical expertise and takes less than 30 minutes.

  • Review all connected apps in your Microsoft and Google accounts. In Microsoft 365 this is found under My Apps and enterprise app permissions. In Google Workspace it is under Security, then Third-party apps with account access. Go through everything listed.
  • Remove anything you do not use or recognize. If you cannot immediately identify what an app is or confirm it is still in active use, remove it. Revoking access from a legitimate app takes minutes to restore. Recovering from a breach caused by a forgotten app takes far longer.
  • Pay close attention to apps with access to email and files. Broad permissions represent the highest level of risk if that app is ever compromised.
  • Make this a regular process, not a one-time clean-up. New apps get connected over time. A quarterly review of connected app permissions is a practical habit that keeps your exposure under control.
  • Extend this review to your team. Individual team members may have connected apps through their own accounts. An organization-wide review ensures nothing is missed.

You may also want to read:

Domain Spoofing: How Attackers Send Emails
From Your Business Address


 

Aurora InfoTech Is Here to Support You

At Aurora InfoTech, we are dedicated to helping business owners build security-aware cultures through proactive IT support and practical security awareness training solutions.

With our team of experts and comprehensive Managed IT Services, we help ensure your systems and data are protected against evolving cyber threats.

 

Book a Cybersecurity
Strategy Session With Us

We can assess where your team's current awareness gaps are, identify the scenarios most relevant to your industry, and help you put a training and verification process in place that actually works.

 CyberTips_Thumbnail
 

Aurora InfoTech
Post by Aurora InfoTech
Sep 21, 2026 8:00 AM