Connected Application Access Review
Applications connected to Google or Microsoft accounts may be able to access profile information, email, files, calendars, contacts or other data. Use this review to identify each connection, understand its permissions and decide whether it should remain.
Applications connected to Google or Microsoft accounts may be able to access profile information, email, files, calendars, contacts or other data. Use this review to identify each connection, understand its permissions and decide whether it should remain.
Review personal and work accounts separately. The controls, visible applications and available actions differ between account types.
Before you begin
Do not remove a critical business integration without first checking whether colleagues or automated processes depend on it. If an application is managed by your organisation, escalate to IT before revoking access.
Step 1 — Choose the account
- ☐ Google personal account
- ☐ Google Workspace account
- ☐ Microsoft personal account (Outlook.com, Hotmail, personal OneDrive, Xbox)
- ☐ Microsoft work or school account
- ☐ Administrator review
- ☐ Individual user review
Step 2 — Create the inventory
For each connected application, record the following:
- ☐ Application name
- ☐ Publisher or developer
- ☐ Account and user
- ☐ Business owner
- ☐ Purpose or use case
- ☐ Date approved (where available)
- ☐ Permissions held
- ☐ Continuing or offline access
- ☐ Last used (where available)
- ☐ Current status
| Application | Publisher | Owner | Purpose | Permissions | Status |
|---|---|---|---|---|---|
Step 3 — Confirm the application
- ☐ I recognise the application
- ☐ The publisher is clearly identified
- ☐ The application is genuine (not an imitation of a known brand)
- ☐ There is a current business purpose
- ☐ A business owner exists
- ☐ The service is still supported by the developer
- ☐ The supplier relationship is active
- ☐ The application appears in the approved software register
Step 4 — Review permissions
Check whether the application may:
- ☐ View basic profile information (name, email address, profile picture)
- ☐ Read contacts
- ☐ Read calendar
- ☐ Edit calendar
- ☐ Read email
- ☐ Send email
- ☐ Read files
- ☐ Edit files
- ☐ Delete files
- ☐ Access photographs
- ☐ Access directory or organisational information
- ☐ Maintain access when not actively signed in
- ☐ Act without an actively signed-in user
Mark each permission as: required | excessive | unclear | prohibited
Step 5 — Assess the risk
| Risk level | Typical indicators |
|---|---|
| Lower | Known publisher, basic profile only, current business purpose, limited permission, clear owner, recently reviewed |
| Medium | Broad permission, legitimate business use, incomplete ownership, older approval, access to business data, unclear retention terms |
| Higher | Unfamiliar application, mailbox access, send-as capability, full file access, continuing offline access, no business owner, unsolicited consent request, unsupported application, former supplier, suspicious publisher, tenant-wide access |
Step 6 — Decide
- ☐ Retain
- ☐ Retain with reduced permissions
- ☐ Seek more information
- ☐ Replace with an approved alternative
- ☐ Revoke user consent
- ☐ Revoke administrator consent
- ☐ Disable application
- ☐ Delete application
- ☐ Escalate for investigation
Record the decision, approver, date, action owner and next review date.
Step 7 — Remove access safely
Before revoking a business application, confirm:
- ☐ Which users depend on this application
- ☐ Whether automated workflows depend on it
- ☐ Whether any data needs to be exported first
- ☐ Whether another sign-in method will be needed
- ☐ Whether the subscription must be cancelled separately
- ☐ Whether the third-party account must be deleted separately
- ☐ Whether the supplier retains previously shared data
- ☐ Whether tokens or sessions require additional revocation steps
- ☐ The action has been recorded
Revoking access closes the connection. It does not automatically delete information the third party has already received, cancel a subscription, or undo actions already performed.
Step 8 — Security follow-up for suspicious applications
Where an application appears suspicious or unexpected:
- ☐ Revoke access
- ☐ Review recent sign-ins
- ☐ Review active sessions
- ☐ Review mailbox and forwarding rules
- ☐ Review file activity
- ☐ Identify other affected users
- ☐ Reset credentials where appropriate
- ☐ Review MFA settings and recovery details
- ☐ Preserve relevant evidence
- ☐ Notify IT or the security team
- ☐ Begin data-breach assessment where required
Step 9 — Schedule the next review
- ☐ Monthly — high-risk environments or large numbers of integrations
- ☐ Quarterly — standard review cycle for most small businesses
- ☐ Six-monthly
- ☐ Annually
- ☐ At supplier contract renewal
- ☐ After role changes
- ☐ During employee offboarding
- ☐ After a security alert or incident
- ☐ After application ownership changes
AI chat safety and connected applications
When using AI services connected to Google or Microsoft accounts, consider whether the AI application holds permissions beyond basic sign-in. Some AI tools request access to email, files or calendar data to provide suggestions or context. Review these permissions using the same process above. For guidance on browser-level risks to AI conversations, see our Browser Extension Security Audit.
Want the full explanation?
Read our Technology Intelligence article for a plain-English explanation of OAuth consent, what connected applications can access, and why changing your password may not be enough.
Plain-English Takeaway
Review which third-party applications are connected to your Google and Microsoft accounts. Remove applications you no longer use or trust, but check important business integrations before revoking them. Changing your password does not necessarily remove existing application permissions, and removing access may not delete information already retained by the third party.
Downloadable guide
Download the Connected Application Access Review
A printable checklist for identifying connected applications, reviewing their permissions and removing unnecessary account access.
Download PDFFree download. No email address required.
Want the full business explanation?
The Technology Intelligence article covers why this matters, where it helps and what to watch out for.
Read the full Technology Intelligence articleRelated Knowledge Centre resources
Browser Extension Security Audit
Identify installed browser extensions, review their permissions and decide which should be approved, restricted or removed from business browsers.
View guidePasskey Setup Guide for Microsoft and Google
Create a more phishing-resistant sign-in method on a trusted device and prepare a safe recovery route before relying on it.
View guideMicrosoft Passkey Readiness Guide
Check which users, devices, authentication policies and recovery procedures your business should review before Microsoft retires its own SMS and voice authentication.
View guide