๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Microsoft 365 Applications

See every application connected to your Microsoft 365 tenant, what it is allowed to do, who approved it and whose data it has reached.

Where to find it
Opened from Microsoft 365 โ€บ Microsoft 365 (the dashboard's applications figures)
Who can use it
Anyone who can see the Microsoft 365 dashboard
Plan
Microsoft 365 monitoring
For
Everyone

What the page is for

Users and administrators can connect third-party applications to Microsoft 365 and grant them access to mail, files and directory data. A malicious or over-privileged app can read data long after anyone remembers approving it. This page lists every application in your tenant with its publisher, permissions and risk, so you can spot the ones that should not be there.

Lavawall flags apps that look risky: apps flagged as suspicious, apps that match a known rogue app, and apps holding a high-risk permission. Apps you have marked as trusted and apps that have been removed are not counted as risky. The count matches the figure on the Microsoft 365 dashboard.

Click any app to see its full details, including who approved it, which users consented, and which users' data it accessed in the background or interactively. Data comes from your connected Microsoft 365 tenant.

What you see

The Microsoft 365 Applications page, with the summary boxes, registered applications header, filters, applications table and application details numbered 1 to 5.
The Microsoft 365 Applications page. Numbers match the list below.
  1. Summary boxes: Total, OAuth, Look risky, Suspicious / rogue, Unverified 3rd party, New (30d) and Removed. Click a box to filter the table to that category; Total clears all filters.
  2. Registered Applications header: the number of apps and Export.
  3. Filters: Search (app name, permission, publisher or app ID), Categories (choose one or more), Publisher, and a reset button.
  4. Applications table: Application, Publisher, Type, Risk, Permissions, Added and Status. Every column sorts.
  5. Application details: a window with the app's publisher and owner, links, consent, its permissions, Approved by, Consented and Users whose data it accessed.

How to find risky applications

  1. Click the Look risky box, or open the page from the risky-apps figure on the Microsoft 365 dashboard.
  2. Check the Risk column: High-risk perms (red), Elevated perms (amber), OK or Trusted. Hover over the badge to see why.
  3. Rows highlighted in red are suspicious or match a known rogue app.

How to review an application

  1. Click the app's name.
  2. Review Publisher, Verified publisher, Owner (Microsoft, your organization or a third party) and the publisher's links.
  3. Review the Permissions list. Each permission shows its type, the resource it applies to, whether it is granted or only requested, its risk and a description.
  4. Check Approved by to see who consented and when.
  5. Check Consented to see whether it has admin consent for all users or which users approved it.
  6. Check Users whose data it accessed for the last background and interactive access by user.

How to filter and export

  1. Type in Search, choose Categories (for example Unverified 3rd party and Has granted permissions) and pick a Publisher.
  2. Click a column heading to sort.
  3. Click Export to download the filtered list as a CSV file.
  4. Click the reset button to clear all filters.

Tips

  • Permission colours run from green (low risk) through yellow and orange to red (high risk). Click the coloured bar in the Permissions column to show all of an app's permissions.
  • Permissions shown in italics are requested but not granted.
  • Third-party apps without a Microsoft verified publisher deserve a closer look.
  • Use New (30d) after an incident to see what was added recently.

Troubleshooting

  • "Publisher details appear after the next Microsoft 365 sync": publisher information is not available yet. Check again after the next sync.
  • "No consent events for this app in the audit history held": Microsoft keeps about 30 days of audit history. Older approvals appear only if Lavawall was already connected at the time.
  • "Could not load applications": refresh the page. If it persists, check that Microsoft 365 is still connected.

Task guides that use this page

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.