TeamsFoxTeamsFox
TeamsFox
  • Home
  • Product
    • By Feature
      • M365 License Management
      • M365 Governance
      • M365 Storage
      • M365 Security
      • Microsoft Copilot Readiness
      • M365 Green IT
    • By Team
      • For IT
      • For Finance and Procurement
      • For Sustainability
  • Pricing
  • Customers
  • Blog
  • Company
    • About Us
    • Contact Us
  • Try for free

Arrived compass prepare an on as. Reasonable particular on my it in sympathize. Size now easy eat hand how. Unwilling he departure elsewhere dejection at. Heart large seems may purse means few blind.

  • ADDRESS:

    California, TX 70240
  • EMAIL:

    support@validtheme.com
  • PHONE:

    +44-20-7328-4499

Get Subscribed!

Who Owns That App? The Entra ID Governance Problem Most Organisations Still Need to Fix

IT security manager searching through unlabelled storage lockers — illustrating the Entra ID app ownership gap where most Microsoft 365 organisations have hundreds of registered applications with no documented owner or review date
  • June 4, 2026

Every Microsoft 365 tenant has hundreds of registered applications. Most have no documented owner, no review date, and broader permissions than anyone intended to grant.

June 2026  |  7 min read

At a Glance

Entra ID app governance risk statistics: 51% of organisations have 250+ apps with read-write M365 access, $4.67M average credential breach cost, 246 days average breach detection time, 80% of breaches involve over-permissioned credentials
51% of organisations have 250 or more Entra ID applications with read-write access to Microsoft 365 data — most with no documented owner and no review date. At $4.67M average breach cost and 246 days average detection time, ungoverned OAuth consent grants are not a compliance checkbox. They are an active financial risk.

1. The Entra ID App Governance Problem in 2026

Every time a user clicks “Accept” on an OAuth consent screen, they grant a third-party application access to their Microsoft 365 data. Email. Calendar. Files. In some cases, the ability to send on their behalf. The permission is recorded in Entra ID. The application appears in the enterprise application list. And in the vast majority of organisations, that is where the governance trail ends.

Research from 2025 found that 51% of organisations have 250 or more Entra ID applications with read-write access to Microsoft 365 data. Most of those applications have no documented owner, no access review schedule, and no expiry. Some were granted access during a project that has since concluded. Others were consented to by users who no longer work at the organisation. A few are connected to vendor accounts that have been inactive for years.

This is not a failure of security policy. It is a failure of Microsoft 365 governance tooling. The access was granted in good faith. The problem is that nobody built a system to review it.

2. How OAuth Consent Grants Create Invisible Access Risks

OAuth consent in Microsoft 365 works in two modes. Delegated permissions act on behalf of the signed-in user, with the user’s level of access. Application permissions act independently of any user, often with tenant-wide scope. Both are legitimate. Both create risk when they are not reviewed.

The risk is not theoretical. An application granted read access to Exchange Online mailboxes can access every email in every mailbox it has permission to reach, including sensitive HR correspondence, legal communications, and executive email, without any authentication event that would trigger a conditional access alert.

Application permissions with write access are higher risk still. An application that can create or modify calendar events, send emails, or update SharePoint content can cause significant damage if its credentials are compromised, or if it is operated by a vendor whose own security posture has weakened since the original consent was granted.

Microsoft’s consent framework includes controls for restricting user consent and requiring admin approval. But controls on new consents do not address the permissions that are already in place. The historical estate is where the exposure sits.

“An application granted read access to Exchange Online mailboxes can access every email in scope without triggering a conditional access alert.”

3. Entra ID App Governance and the Lifecycle Problem: Apps That Nobody Owns

The immediate risk from misconfigured OAuth consents is significant. But the structural problem is lifecycle. Applications accumulate faster than they are decommissioned. And without a formal ownership and review process, the accumulation is one-directional.

A project team integrates a third-party project management tool with Microsoft 365. The OAuth consent is granted by the IT admin on request. The project completes eighteen months later. The team moves on. The tool subscription lapses. The Entra ID application registration and the OAuth consent remain, along with whatever access permissions were configured during the integration.

Multiply this pattern across three years of projects, vendor integrations, and user-initiated tool adoptions, and the result is an application estate where a significant proportion of the access grants are serving no active business purpose. They represent pure risk: access that nobody needs, owned by nobody, reviewed by nobody.

Microsoft provides Entra ID access reviews as a mechanism for periodic recertification. These are effective when configured and used. The gap is that most organisations have not extended their access review programmes to cover application permissions, only user and group memberships.

4. What Over-Permissioned Apps and Privileged Credentials Have in Common

The connection between Entra ID app governance and breach risk is direct. Forrester research found that 80% of security breaches involve privileged or over-permissioned credentials. IBM’s Cost of a Data Breach report puts the average cost of a credential-based breach at $4.67 million, with an average detection time of 246 days.

An Entra ID application with tenant-wide read-write access to Exchange Online is, in effect, a privileged credential. If the application’s client secret is compromised, leaked through a vendor’s own breach, or left in a code repository, the attacker inherits all of the permissions that were granted to the application. The access is persistent, has no multi-factor authentication requirement, and may not trigger conditional access policies that would flag a human login from an unusual location.

RISK: Application credentials with read-write access to Exchange Online or SharePoint do not require MFA and may not be subject to conditional access policies. A compromised app secret provides persistent, undetected access for an average of 246 days. (IBM, 2025)

5. Entra ID app governance: Building an Entra ID Application Governance Programme

An effective Entra ID app governance programme addresses four areas.

Inventory and classification. A complete list of every registered application and enterprise application in the tenant, with its permission scope, consent type, last activity date, and assigned owner. Without this baseline, nothing else is possible.

Ownership assignment. Every application needs a named owner who is responsible for reviewing its access annually, confirming whether it is still in use, and initiating decommissioning when it is not. Applications without an active owner should be flagged immediately.

Periodic access reviews. Extending the Entra ID security access review process to cover application permissions, not just user and group memberships. High-risk applications, those with write access, tenant-wide scope, or access to sensitive data, should be reviewed more frequently.

Consent policy controls. Restricting user-initiated consent to low-risk, verified publisher applications. Requiring admin approval for any application requesting write permissions or access to sensitive data categories. These controls prevent new accumulation while the existing estate is reviewed.

6. How TeamsFox Surfaces Entra ID Governance Gaps Across Your Tenant

TeamsFox provides tenant-wide visibility into Entra ID application registrations, OAuth consent grants, and permission scopes alongside the rest of the Microsoft 365 estate. Orphaned applications, those with no recent activity and no active owner, are surfaced automatically. Applications with high-risk permission combinations, write access combined with broad scope, are flagged for review.

The connection to licence management is also visible: applications that are no longer in use often correspond to lapsed vendor subscriptions or completed projects, creating an opportunity to reclaim both the access and any associated licence costs.

For IT security teams and CISOs assessing their exposure, a free Microsoft 365 tenant analysis from TeamsFox shows the current Entra ID application estate, including permission scope, activity status, and ownership gaps, without requiring any configuration changes or agent installation.

About TeamsFox

TeamsFox is the Microsoft 365 governance and optimisation platform that gives IT and security teams real-time visibility into licence usage, Entra ID access risk, storage waste, and agent sprawl. Headquartered in Düsseldorf and trusted in 20+ countries, TeamsFox helps organisations reduce Microsoft 365 licence spend by up to 30%, cut storage costs by 40%, and close governance gaps before they become breaches.

See Your Entra ID Exposure: Free Microsoft 365 Tenant Analysis

Share:

Previus Post
Enterprise AI

Leave a comment

Cancel reply

Categories

  • Copilot Readiness
  • Governance
  • Green IT
  • License Optimization

Recent Posts

  • IT security manager searching through unlabelled storage lockers — illustrating the Entra ID app ownership gap where most Microsoft 365 organisations have hundreds of registered applications with no documented owner or review date
    04 June, 2026Who Owns That App?
  • Man watching water overflow uncontrollably from a kitchen tap — illustrating ungoverned Microsoft 365 AI spending across Copilot licences, agent metered billing, Power Platform credits, and shadow AI subscriptions
    04 June, 2026Enterprise AI Spending Is
  • CFO unwrapping an unused office chair still in packaging — illustrating the hidden cost of Microsoft 365 over-licensing and wasted spend on unused licences and underutilised workloads
    04 June, 2026The Hidden Cost of
  • IT manager reviewing technical blueprints — illustrating the process of building a Microsoft 365 governance framework from scratch within a practical 90-day plan
    04 June, 2026How to Build a

Tags

Access Control Access Management AI agent governance AI Governance Azure Cool Storage Compliance Management copilot Copilot data governance Copilot Studio governance Data Governance Data Security Entra ID governance Identity security Microsoft 365 Information Protection license management License Optimization M365 compliance audit log Microsoft 365 Microsoft 365 AI agents Microsoft 365 Copilot deployment Microsoft 365 cost reduction Microsoft 365 E7 Microsoft 365 governance Microsoft 365 governance visibility Microsoft 365 licence automation Microsoft 365 licence hygiene Microsoft 365 licence optimisation Microsoft 365 licensing renewal Microsoft 365 Management Microsoft 365 real-time analytics Microsoft 365 rightsizing Microsoft 365 storage management Microsoft 365 storage optimization Microsoft Copilot business case Microsoft Copilot readiness Microsoft EA CSP MCA Microsoft licence cost optimisation NIS2 compliance Risk Management ROT data ROT Data ROT data SharePoint SaaS licence waste SharePoint storage optimisation SharePoint storage waste

Quick Links

  • Home
  • Customers
  • Blog
  • Pricing
  • About Us
  • Contact Us

How We Help

  • M365 License Management
  • M365 Governance
  • M365 Storage
  • M365 Security
  • Microsoft Copilot Readiness
  • M365 Green IT
Contact Info
ADDRESS Erkrather Str. 401, 40233 Düsseldorf, Germany
ADDRESS 1 Rue Marguerin, 75014 Paris, France
EMAIL contact@teamsfox.com

Copyright 2026 TeamsFox. All Rights Reserved by TeamsFox GmbH

  • Legal Notice
  • Privacy Policy
  • Terms of Use
  • EULA