Multi-CloudHow-To & HardeningRetrospectives

How to Audit SaaS-to-SaaS OAuth Integrations and Token Scopes

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2025, written in 2026 with the benefit of hindsight.

SaaS-to-SaaS integrations hold OAuth tokens that can read and export your data. The Salesloft Drift campaign showed how one compromised vendor can reach hundreds of customers. Here is how to audit integrations and their scopes.

Step 1: Inventory connected apps

  • Microsoft 365 / Entra ID: Enterprise applications with delegated and application permissions; Defender for Cloud Apps app governance.
  • Salesforce: Connected Apps and Connected Apps OAuth Usage in Setup.
  • Google Workspace: App access control in the Admin console.
  • GitHub, Slack, Atlassian, others: installed apps and OAuth authorizations.

Defender for Cloud Apps and SaaS security posture management tools can consolidate this view across platforms.

Step 2: Record for each integration

  • Vendor and business owner.
  • Scopes and permissions (read all data? write? admin?).
  • Users or service accounts the token belongs to.
  • Last used.

Step 3: Reduce scope

  • Remove integrations not used in 90 days.
  • Ask vendors for least-privilege scopes.
  • In Salesforce, use connected app policies: admin-approved users only, IP restrictions, and refresh token policies limiting token lifetime.
  • In Entra ID, restrict app access to specific mailboxes or sites where supported.

Step 4: Protect integration accounts

If integrations run as a dedicated integration user, restrict that user's profile and permissions.

Step 5: Remove secrets from SaaS data

Scan CRM records, support tickets and notes for credentials, and rotate anything found.

Step 6: Monitor

Stream SaaS audit logs (Salesforce Event Monitoring, Microsoft 365 audit) to your SIEM. Alert on bulk exports and API calls from new IPs.

Verify

Quarterly integration review with owners.

audit saas oauth integrationsSalesloft Drift OAuth2025

More on this story