baref00t.io

// packs / oauth-app-risk

OAuth App & Consent-Grant Risk Audit

Global

OAuth App Risk Pack | Global

Every app a user or admin ever consented to is a standing key into your tenant. This audit inventories them all — delegated grants and application permissions — and ranks which to revoke first.

One-off
$399

Single report, no commitment.

Monthly
$99/month

Continuous monitoring — fresh report every 30 days.

Available in AUD, USD, GBP, EUR, SGD. MSP partners get volume discounts via the partner programme.

What it scores

OAR1

Consented inventory

delegated grants + application (app-role) permissions, third-party share

OAR2

High-risk permissions

crown-jewel app-only scopes (Mail, Files, Sites, Directory, roles)

OAR3

Publisher trust

unverified-publisher apps holding application permissions

OAR4

Consent-phishing shape

offline_access + mail/file data on user-consented third-party apps

OAR5

Dormancy

granted apps with no sign-in in 90+ days (requires Entra ID P1)

OAR6

Ranked revoke queue

prioritised remediation list — read-only, no tenant changes made

Microsoft APIs

  • Microsoft Graph (universal scopes, read-only across the tenant)
  • Azure REST (when the product reads Azure subscription posture)
  • Defender + Intune APIs where applicable

Customer prerequisites

  • Microsoft 365 tenant with admin-consent capability
  • Global Reader or equivalent for the consenting admin
  • No agent installs, no infrastructure changes required
  • Report delivered by email within 10 minutes of consent