DEV Community

Serguey Shinder
Serguey Shinder

Posted on

Forty One Applications Could Read Our Mail and None of Them Went Through Procurement

We ran a report on third party applications holding delegated access to our productivity platform, expecting a handful. The report came back with forty one, of which we recognised nine.

None of them were installed by IT, and none of them had bypassed a control. Every one had been authorised by an employee clicking through a consent screen that asked, in reasonable language, for permission to read mail, read and write files, or access the calendar on their behalf. Users approved them because the tools were useful. A meeting transcription service. Two scheduling assistants. A signature manager. A note taker that a team trialled for a fortnight in 2024 and forgot about, whose token had never expired and whose vendor had since been acquired by a company none of us could name.

What makes this different from ordinary shadow IT is the shape of the access. A rogue spreadsheet holds a copy of some data. A consented application holds a live, continuous, revocable-in-theory grant against the real mailbox, and it keeps that grant when the employee changes role, goes on leave, or leaves entirely. Several of the tokens we found belonged to people who had left the organisation; the account was disabled, the application's access was not. Two of the applications requested tenant wide scopes rather than personal ones, which means an administrator had approved them at some point, probably in a hurry, probably during a rollout.

Our procurement process is thorough about vendors that send an invoice. It has nothing to say about a free tool that a user grants read access to twelve years of correspondence.

The remediation was straightforward once we could see it. User consent for anything requesting sensitive scopes now goes to an approval queue rather than to the user's own judgement. Existing grants were reviewed, and roughly half were revoked with no complaints, which tells you how much they were being used. Tokens now expire and have to be renewed. Leaver processing revokes application grants as well as disabling the account, which it had never done.

The uncomfortable part was not the finding. It was that the data had been leaving for years through a door we had built and never watched.

– Serguey Shinder

Top comments (1)

Some comments may only be visible to logged-in visitors. Sign in to view all comments.