Knowledge Centre
Cyber Security GuidesChecklist and Guide

Connected Application Access Review

10 minutes to completeEvergreen guide — kept up to date

Applications connected to Google or Microsoft accounts may be able to access profile information, email, files, calendars, contacts or other data. Use this review to identify each connection, understand its permissions and decide whether it should remain.

Applications connected to Google or Microsoft accounts may be able to access profile information, email, files, calendars, contacts or other data. Use this review to identify each connection, understand its permissions and decide whether it should remain.

Review personal and work accounts separately. The controls, visible applications and available actions differ between account types.

Before you begin

Do not remove a critical business integration without first checking whether colleagues or automated processes depend on it. If an application is managed by your organisation, escalate to IT before revoking access.

Step 1 — Choose the account

  • ☐ Google personal account
  • ☐ Google Workspace account
  • ☐ Microsoft personal account (Outlook.com, Hotmail, personal OneDrive, Xbox)
  • ☐ Microsoft work or school account
  • ☐ Administrator review
  • ☐ Individual user review

Step 2 — Create the inventory

For each connected application, record the following:

  • ☐ Application name
  • ☐ Publisher or developer
  • ☐ Account and user
  • ☐ Business owner
  • ☐ Purpose or use case
  • ☐ Date approved (where available)
  • ☐ Permissions held
  • ☐ Continuing or offline access
  • ☐ Last used (where available)
  • ☐ Current status
ApplicationPublisherOwnerPurposePermissionsStatus

Step 3 — Confirm the application

  • ☐ I recognise the application
  • ☐ The publisher is clearly identified
  • ☐ The application is genuine (not an imitation of a known brand)
  • ☐ There is a current business purpose
  • ☐ A business owner exists
  • ☐ The service is still supported by the developer
  • ☐ The supplier relationship is active
  • ☐ The application appears in the approved software register

Step 4 — Review permissions

Check whether the application may:

  • ☐ View basic profile information (name, email address, profile picture)
  • ☐ Read contacts
  • ☐ Read calendar
  • ☐ Edit calendar
  • ☐ Read email
  • ☐ Send email
  • ☐ Read files
  • ☐ Edit files
  • ☐ Delete files
  • ☐ Access photographs
  • ☐ Access directory or organisational information
  • ☐ Maintain access when not actively signed in
  • ☐ Act without an actively signed-in user

Mark each permission as: required | excessive | unclear | prohibited

Step 5 — Assess the risk

Risk levelTypical indicators
LowerKnown publisher, basic profile only, current business purpose, limited permission, clear owner, recently reviewed
MediumBroad permission, legitimate business use, incomplete ownership, older approval, access to business data, unclear retention terms
HigherUnfamiliar application, mailbox access, send-as capability, full file access, continuing offline access, no business owner, unsolicited consent request, unsupported application, former supplier, suspicious publisher, tenant-wide access

Step 6 — Decide

  • ☐ Retain
  • ☐ Retain with reduced permissions
  • ☐ Seek more information
  • ☐ Replace with an approved alternative
  • ☐ Revoke user consent
  • ☐ Revoke administrator consent
  • ☐ Disable application
  • ☐ Delete application
  • ☐ Escalate for investigation

Record the decision, approver, date, action owner and next review date.

Step 7 — Remove access safely

Before revoking a business application, confirm:

  • ☐ Which users depend on this application
  • ☐ Whether automated workflows depend on it
  • ☐ Whether any data needs to be exported first
  • ☐ Whether another sign-in method will be needed
  • ☐ Whether the subscription must be cancelled separately
  • ☐ Whether the third-party account must be deleted separately
  • ☐ Whether the supplier retains previously shared data
  • ☐ Whether tokens or sessions require additional revocation steps
  • ☐ The action has been recorded

Revoking access closes the connection. It does not automatically delete information the third party has already received, cancel a subscription, or undo actions already performed.

Step 8 — Security follow-up for suspicious applications

Where an application appears suspicious or unexpected:

  • ☐ Revoke access
  • ☐ Review recent sign-ins
  • ☐ Review active sessions
  • ☐ Review mailbox and forwarding rules
  • ☐ Review file activity
  • ☐ Identify other affected users
  • ☐ Reset credentials where appropriate
  • ☐ Review MFA settings and recovery details
  • ☐ Preserve relevant evidence
  • ☐ Notify IT or the security team
  • ☐ Begin data-breach assessment where required

Step 9 — Schedule the next review

  • ☐ Monthly — high-risk environments or large numbers of integrations
  • ☐ Quarterly — standard review cycle for most small businesses
  • ☐ Six-monthly
  • ☐ Annually
  • ☐ At supplier contract renewal
  • ☐ After role changes
  • ☐ During employee offboarding
  • ☐ After a security alert or incident
  • ☐ After application ownership changes

AI chat safety and connected applications

When using AI services connected to Google or Microsoft accounts, consider whether the AI application holds permissions beyond basic sign-in. Some AI tools request access to email, files or calendar data to provide suggestions or context. Review these permissions using the same process above. For guidance on browser-level risks to AI conversations, see our Browser Extension Security Audit.

View the Browser Extension Security Audit

Want the full explanation?

Read our Technology Intelligence article for a plain-English explanation of OAuth consent, what connected applications can access, and why changing your password may not be enough.

Which Apps Can Access Your Google or Microsoft Account?

Plain-English Takeaway

Review which third-party applications are connected to your Google and Microsoft accounts. Remove applications you no longer use or trust, but check important business integrations before revoking them. Changing your password does not necessarily remove existing application permissions, and removing access may not delete information already retained by the third party.

Downloadable guide

Download the Connected Application Access Review

A printable checklist for identifying connected applications, reviewing their permissions and removing unnecessary account access.

Download PDF

Free download. No email address required.

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.