Tenant security review
Consented, read-only configuration and metadata · no mail, files, or content
Every Microsoft 365 tenant I've seen scanned has at least one, and most have a dozen: an application, connected years ago, holding permissions nobody can explain, with credentials that still work.
It happens without anyone planning it. In 2019 somebody in marketing trialed an email tool. It asked for access, they clicked accept, the trial ended, everyone forgot. In 2021 a consultant connected a reporting app to build a dashboard for a project that wrapped eight months later. The consultant is gone. The app isn't. Somewhere along the way an IT vendor registered an application for a migration and gave it broad permissions to make the weekend go smoothly. The migration finished. The permissions didn't.
None of these were mistakes at the time. Each one was a reasonable person solving a real problem. But OAuth grants don't expire when the problem does. They sit there, valid, accumulating like sediment. The tenant is five years old and nobody has ever audited the pile, because auditing the pile isn't anyone's job.
Now the dangerous part. Some of those applications hold standing credentials, secrets and certificates that authenticate without a human present. A few hold permissions like reading all mail or writing to all sites. An app with a live credential and broad permissions is functionally an admin account that no one monitors, attached to a vendor that may no longer exist, secured by whatever practices that vendor had in 2019. Attackers figured this out a while ago. Compromising a forgotten app is quieter than phishing a user, because there's no user to notice.
When I say some findings sell themselves, this is the one I mean. You don't need to explain threat landscapes to a business owner. You put down one page: here are 34 applications with access to your company's data. Here are the six with admin-level permissions. Here are the four nobody in your company can identify. Then you stop talking. The owner does the selling from there, usually starting with some version of "who approved these?"
The answer, of course, is everyone and no one. That's the point. Grant sprawl is nobody's fault and everybody's problem, which makes cleaning it up the easiest project approval in managed services. It costs little, it removes real risk, and the before-and-after is visible on the next scorecard: 34 apps down to 11, zero unexplained, zero stale credentials.
Dead apps with live keys. Every tenant has them. Be the one who finds them.