How to review OAuth app permissions before approving access
OAuth approvals can look harmless because the screen says connect, allow, and continue. In a company account, that button can grant more access than people realize. I have reviewed apps that only needed calendar read access but asked for full mailbox access, offline tokens, and permission to manage files. Nobody was trying to be careless. The approval screen just made the risk look normal. Before…