Microsoft 365 Data Exposure Assessment
Find the third-party apps that hold high-risk permissions to your Microsoft 365 data — the app-consent exposure most admins have never reviewed. Read-only, and free to run.
Read-only. It reviews consent grants — it never opens file or mailbox contents.
Microsoft 365 data exposure is any unintended path to your data. M365 Health Score focuses on one of the most overlooked paths: third-party application consent. It finds non-first-party apps in your tenant that were granted high-risk Microsoft Graph permissions, and lists exactly what each one can reach.
What it checks today
The assessment enumerates the OAuth permission grants in your directory, filters out Microsoft’s own first-party apps and apps owned within your tenant, and flags any remaining third-party application that holds high-risk Graph permissions — the scopes that would let an app read broadly across directory, mail or files. For each one you get the app’s name and the specific risky permissions it was granted, with a pointer to review it in Entra ID → Enterprise Applications.
This is deliberately a narrow, high-signal check — not a full data-governance scan. It does not yet audit SharePoint or OneDrive sharing links, and it does not review DLP, sensitivity labels or retention. A SharePoint/OneDrive external-sharing check is in development; this page will be updated when it ships.
Why app consent is worth checking first
Consent is sticky. An app a single user approved a year ago can keep broad read access to organizational data indefinitely — and because that access is token-based, it survives password resets and MFA. Malicious OAuth apps exploit exactly this. Reviewing which third-party apps hold high-risk permissions is one of the highest-signal, lowest-effort data-exposure checks you can run.
Microsoft 365 data exposure FAQ
What is Microsoft 365 data exposure?
Data exposure is any way your Microsoft 365 data can be reached that you didn’t intend. One of the most overlooked routes is third-party application consent: an app a user once approved may hold standing, high-risk permissions to read directory, mail or files across the tenant.
What does this assessment actually check?
Today it checks one thing thoroughly: third-party (non-first-party) applications in your tenant that hold high-risk Microsoft Graph permissions. It lists each app and the risky permissions it was granted, so you can review and revoke what isn’t needed.
Does it scan the contents of my files or SharePoint sites?
No. It does not open file contents, and it does not currently enumerate SharePoint or OneDrive sharing links. It reads the app-consent grants in your directory. A SharePoint/OneDrive external-sharing check is on the roadmap and this page will be updated when it ships.
Why is app consent a data-exposure risk?
Consent persists. An app approved months ago — sometimes by a single user — can retain broad read access to organizational data long after anyone remembers it exists. Attackers also use malicious OAuth apps precisely because the access survives password changes and MFA.
Review your app-consent exposure
See which third-party apps hold high-risk permissions to your tenant — read-only, free to run.