Resources
Practical guides to seeing — and tightening — who and what can access your Google Workspace and Microsoft 365.
Finding ex-employee access that survives offboarding
Former-employee access hides in OAuth tokens, app passwords, forwarding rules, and shared files. This guide covers where to look in Google Workspace and Microsoft 365.
Admin consent and org-wide app grants in Microsoft 365, explained
One admin click can give a third-party app access to every mailbox and file in your tenant. This guide explains admin consent in Microsoft 365 and how to review what's been granted.
Using an access audit to answer your cyber-insurance questionnaire
Cyber-insurance applications ask detailed access-control questions. An access audit of your Google Workspace or Microsoft 365 turns each answer into documented evidence.
Finding admin accounts without MFA in Microsoft 365
Privileged accounts without multi-factor authentication are the biggest breach risk in Microsoft 365. This guide shows how to find the gaps, including the ones Conditional Access misses.
Risky OAuth scopes, explained
What OAuth scopes are and how to tell whether a connected app in Google Workspace or Microsoft 365 holds more access than it needs.
How to find the third-party apps with access to your Microsoft 365
Every enterprise app, OAuth grant, and service principal with access to your Microsoft 365 / Entra ID tenant shows up in one place. This guide walks that inventory and picks out the risky grants.
How to find the third-party apps with access to your Google Workspace
Where the Google Admin console lists every third-party app and OAuth token connected to your Workspace, and how to spot the risky ones in that list.