Microsoft 365CIO BriefingsRetrospectives

CIO Brief: Who Approved That App? Governing OAuth Permissions

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2018, written in 2026 with the benefit of hindsight.

The short version: Cambridge Analytica obtained data on tens of millions of Facebook users through an app most of them never used. The same mechanism — apps requesting access to your data — exists in Microsoft 365, and attackers use it.

Why app permissions are a governance issue

When an employee clicks "Accept" on an app permission screen, they may give that app ongoing access to their email, files or calendar. Some permissions reach other people's data too. Many organizations have hundreds of such apps connected, and few have reviewed them.

The business impact

  • Data exposure to app vendors, legitimate or not.
  • Persistent attacker access: malicious apps keep working after password resets and MFA.
  • Compliance risk: data shared with unvetted third parties may violate privacy commitments.

Questions to ask your team

  • How many third-party apps have access to our Microsoft 365 data?
  • Can employees approve apps on their own, and for what level of access?
  • Do we review apps that can read everyone's mail or files?
  • How do employees request a new app, and how long does it take?

What good looks like

Employees can approve only low-risk apps from verified publishers; anything more goes through a quick admin review; high-access apps are reviewed regularly and removed when unused.

The decision

Ask for a list of the apps with the broadest access to company data, and a recommendation on user consent settings. It is usually a single settings change with outsized benefit.

cambridge analytica oauth impactCambridge Analytica / OAuth2018

More on this story