// packs / oauth-app-risk
OAuth App & Consent-Grant Risk Audit
GlobalOAuth App Risk Pack | Global
Every app a user or admin ever consented to is a standing key into your tenant. This audit inventories them all — delegated grants and application permissions — and ranks which to revoke first.
Single report, no commitment.
Continuous monitoring — fresh report every 30 days.
Available in AUD, USD, GBP, EUR, SGD. MSP partners get volume discounts via the partner programme.
What it scores
Consented inventory
delegated grants + application (app-role) permissions, third-party share
High-risk permissions
crown-jewel app-only scopes (Mail, Files, Sites, Directory, roles)
Publisher trust
unverified-publisher apps holding application permissions
Consent-phishing shape
offline_access + mail/file data on user-consented third-party apps
Dormancy
granted apps with no sign-in in 90+ days (requires Entra ID P1)
Ranked revoke queue
prioritised remediation list — read-only, no tenant changes made
Microsoft APIs
- Microsoft Graph (universal scopes, read-only across the tenant)
- Azure REST (when the product reads Azure subscription posture)
- Defender + Intune APIs where applicable
Customer prerequisites
- Microsoft 365 tenant with admin-consent capability
- Global Reader or equivalent for the consenting admin
- No agent installs, no infrastructure changes required
- Report delivered by email within 10 minutes of consent
Other Packs
Deep-dive into your identity attack surface — the #1 breach vector. Six dimensions covering every aspect of your Entra I…
Full email attack surface analysis — spoofing, phishing, data leakage, and mail flow hygiene across your Microsoft 365 t…
Find where your sensitive data is exposed right now — misconfigured sharing, labelling gaps, guest sprawl, and excessive…