Skip to main content

Posts

Showing posts from March, 2026

How to Review and Clean Up OAuth App Access in Google Workspace and Microsoft 365

Most school districts have dozens, sometimes hundreds, of third-party apps connected to staff and student accounts. Some are intentional. Many are forgotten . A few are risky. These apps often have access to: email files contacts calendars even full account data And the reality is, most districts rarely review them. This is one of the easiest ways to reduce risk without buying a single new tool. Why This Matters OAuth-connected apps don’t need passwords; they rely on permissions granted by users. That means: A teacher clicks “Allow” once The app may keep access indefinitely IT may never know it exists Over time, this creates: hidden data exposure unnecessary access to student information increased risk if an app is compromised Cleaning this up is quick, impactful, and often overdue. Step 1: Review OAuth Apps in Google Workspace Navigate to: Admin Console → Security → Access and Data Control → API Controls → App Access Control What You’ll See: A list of third-party apps connected to yo...