SaaS to SaaS OAuth Integrations: The Access You Never Reviewed

SaaS to SaaS OAuth Integrations: The Access You Never Reviewed

A salesperson connects a meeting transcription tool to the calendar and mailbox. A marketer links an analytics product to the customer database. Each connection takes one click, grants standing access through a token, and appears on no register. The NCSC’s supply chain security guidance asks organisations to understand who they depend on, and these integrations are dependencies nobody recorded.

Why this differs from buying software

Procurement reviews the software you pay for. These connections are usually free tiers or trials adopted by an individual, so they never reach procurement, legal or IT. The access granted often exceeds what the tool needs, because permission sets are coarse and the consent screen offers no way to negotiate. The result is a set of third parties holding read access to email, files or customer records, with no contract, no data processing agreement and no security review behind them. Nobody signed anything, so there is nothing to fall back on when something goes wrong.

What a breach at one of them means for you

If a connected vendor is compromised, the attacker inherits every token that vendor holds, including yours. That access continues to work regardless of your password policy, your multi-factor authentication and your Conditional Access rules, because the token was legitimately issued and is being used through the vendor’s own integration. Several large incidents in recent years have followed this shape: one supplier compromised, hundreds of customer tenants accessed, and the customers finding out from the supplier’s disclosure rather than their own monitoring. Revocation falls to you as well, because only you can remove a grant made in your own tenant.

“Pull the list of connected applications in your Microsoft or Google tenant and read it with the department heads. Every review I have run produced at least one product nobody could name and one that had not been used in over a year while still holding mailbox access. Removing those takes an afternoon and closes a door you did not know was open.”

William Fieldhouse, Director, Aardwolf Security Ltd

Getting control without blocking everything

Blanket restriction pushes people towards workarounds, so aim for visibility with a light approval path. Restrict user consent to low impact permissions from verified publishers, and route anything broader through a request that a named person reviews within a working day. Publish a short list of approved tools so the common requests never need a decision at all, and say plainly which categories will never be approved, such as anything requesting access to every mailbox in the organisation. Then review the connected applications monthly, looking at permissions granted, last use and who authorised each one.

Fitting it into your assurance work

Treat connected applications as part of your attack surface rather than a procurement footnote. Cloud tenant penetration testing checks whether a low privilege user can still connect an application with broad permissions, which is the control that actually decides your exposure. Add the vendors holding significant access to your supplier review list, ask them for their own testing evidence, and keep ongoing vulnerability assessment running on the systems those integrations reach, since the data path runs both ways.

See also: Advanced Data Loss Protection Solutions for Business Security

Frequently asked questions about connected applications

These questions come up when a tenant review reaches the integrations list.

Does removing an application break anything?

Sometimes, which is why you check last use first. Applications with no activity for ninety days are usually safe to revoke, and notifying the department beforehand converts a support call into a short conversation.

Are marketplace applications reviewed by the platform?

Verification confirms publisher identity and basic listing requirements rather than security. Treat verified status as a signal, not an assessment, and apply your own review for anything touching customer data.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *