Microsoft Entra ID App Consent Review
Reviews delegated grants, application permissions, and directory roles held by apps in an Entra ID tenant, and proposes which to revoke, restrict, or keep.
What this agent does
This read-only agent reviews application access in a Microsoft Entra ID tenant. It lists the service principals, the delegated permissions users and admins consented to, the application permissions granted to apps, and the directory roles held by apps. It ranks each by the sensitivity of its permissions, the number of users who consented, its last sign-in, whether the publisher is verified, and whether it is multi-tenant. It proposes which grants to revoke, which apps to restrict, and which to keep, with the evidence for each. A person makes every change.
The challenge
An Entra ID application permission such as Mail.Read reads every mailbox in the tenant with no user present. An app registration built for a migration keeps Directory.ReadWrite.All after the migration ends. A multi-tenant app from an unverified publisher holds delegated consent from many users. A permissive user consent setting lets any user grant a new app access to their mail and files. Nobody reviews the delegated and application permissions side by side.
The solution
The agent reads every grant and service principal in one pass. It separates permissions that act as a user from permissions that act as the app. It states each permission in plain words, such as read all mail or write directory data. It proposes the narrowest change for each item and presents every proposal as a candidate. Provides a ranked queue of app access, with the evidence for each proposal.
Workflow
- 01
List applications
List service principals with their publisher verification, tenant of origin, owners, directory roles, and last sign-in.
- 02
List grants
List delegated permission grants by user and by admin, and application permission grants, with the permission, the consent date, and who consented.
- 03
Rank
Rank each app by permission sensitivity, consent count, last sign-in, publisher, and consent type.
- 04
Propose
Write a revoke, restrict, or keep proposal per item with the evidence.
- 05
Report
Publish the ranked queue with each proposal and the current user consent policy.
Agent template
# Microsoft Entra ID App Consent Review
## Measurable outcomes
Every service principal and permission grant in the tenant is in the ranked queue. Each one has its permissions in plain words and a proposal. Track the apps flagged by at least one rule. A proposal counts as applied when the next run finds the grant removed or narrowed.
## Procedure
Each run, list every service principal in the tenant with its publisher and verification status, its tenant of origin, its owners, and the directory roles it holds. Exclude Microsoft first-party apps unless I include them. Take each app's last sign-in from the service principal sign-in activity report. For each app, list the delegated permission grants with the permission, whether a user or an admin consented, and the consenting user. Take the consent date for delegated grants from the audit log, and report it as unknown when the grant predates log retention. List the application permissions granted to each app with the assignment date. Translate each permission into plain words, such as read all mail, send mail as any user, read and write all directory data, read all files, or act offline on the user's behalf. Rank each app by the most sensitive permission it holds, weighted by the number of users who consented. Lower the rank for apps with a sign-in in the last 30 days. Lower the rank for apps from verified publishers. Lower the rank for apps I mark as approved. Flag apps with no sign-in in 90 days from the service principal sign-in activity report. Flag grants from disabled or deleted users. Flag apps from unverified publishers with user consent. Flag multi-tenant apps that hold application permissions. Flag apps that hold directory write or mail permissions that no approved use needs. Flag apps with a privileged directory role. Read the user consent policy. Flag a setting that lets users consent to permissions beyond the low-impact set without an admin review. For each app, propose one of revoke, restrict, or keep. Revoke means remove the grants or disable sign-in for the service principal. Restrict means remove specific permissions, require admin consent, or assign the app to a group. Restrict can also mean scope mail permissions to named mailboxes with Exchange RBAC for Applications. Keep means the use is approved and the permissions match it. Give the evidence for each proposal, such as the permissions, the consent count, the last sign-in, and the publisher. Present every proposal as a candidate and change nothing. Never revoke a grant, disable a service principal, or change the consent policy.
## Requirements
It needs read-only Microsoft Graph access to service principals, applications, delegated permission grants, application role assignments, directory roles, the consent policy, the sign-in activity reports, and the audit logs, and nothing more. It never changes applications, grants, roles, or settings. Reports show app names, permissions, and counts. User names appear as stable pseudonyms. Related templates
-
Microsoft Entra ID Offboarding Verification
Checks each departed user for an account re-enabled by sync, owned apps with valid secrets, and access outside Entra ID, and reports each open path.
Identity and Access 9 tools -
Microsoft Entra ID Posture Report
Delivers a weekly Entra ID report on permanent privileged roles, Conditional Access changes, and expiring app credentials, with what changed since last week.
Identity and Access / Reporting and Compliance 1 tools -
Google Workspace App Access Review
Reviews third-party OAuth apps, their per-user tokens, and domain-wide delegations in a Google Workspace domain, and proposes which to block, restrict, remove, or keep.
Identity and Access 1 tools -
Google Workspace Offboarding Verification
Checks each departed user for Drive files shared outside the domain, live OAuth tokens, and access outside Workspace, and reports each open path.
Identity and Access 9 tools