Blind-Spot

A Claimed World First Exposes a Microsoft 365 Blind Spot

What IT Teams Should Check Before Migrating

Published 20 August 2026

This paper raises a valuable question for IT managers, migration consultants and MSPs …

What Were the Researchers Looking For?

Spying-App

Apps have become an integral part of life, but how can you tell if their access is excessive?

Building a Picture of the App Ecosystem

Gathering the necessary information wasn’t as simple as browsing a single Microsoft app store. Microsoft 365 applications reach users through several distribution channels, including the Teams® and Office add-in stores, Microsoft Marketplace and third-party integrations.

The researchers used these various sources to identify apps and collect descriptions of what they claimed to do. Their September 2025 Marketplace crawl identified 8,232 unique apps across Teams, Outlook®, Word™, Excel™, PowerPoint™ and SharePoint®.

The harder part was collecting permissions data. That information is presented inconsistently across different channels, so the researchers installed hundreds of apps in a dedicated Microsoft 365 test tenant and inspected their effective OAuth permissions through Entra ID (a cloud-based identity and access management service, formerly known as Azure Active Directory). They supplemented this with anonymized information about apps used in an operational university tenant.

After matching descriptions with permission sets, removing duplicates and filtering unsuitable records, they arrived at 1,069 apps for which they had both a usable description and associated permissions.

That was the dataset used for the main anomaly analysis.

What Did They Find?

What gives the figure more weight is what happened next.

They were looking for permission patterns that stood out from those of an app’s functional peers. Using several anomaly-detection methods, they flagged 139 apps, or about 13% of the analyzed dataset, as essentially having something unusual or uncommon about their permissions compared with other apps of the same type.

Why This Matters During a Migration

That makes migration an excellent time to review third-party apps. Ask the useful questions: Who owns this app? What process does it support? Which users depend on it? What can it access? Does that access still make sense? Will it still be needed after migration?

A tool used by 500 people deserves attention, but so does the one used by a single person who produces the month-end financial report.

Who-Does-It-Belong-To

Who does it belong to? What does it do? Do you need it after the migration?

Access Is Only One Dependency Layer

Recommended: Build Two Dependency Maps

Broad permissions can be legitimate, but they should never be hidden or mysterious.

The first is an access map. It identifies which users, groups and applications can reach organizational resources and what permissions have been granted.

The second is a content dependency map. It identifies links inside files, the resources those links depend on and the locations likely to change.

One helps control exposure. The other helps preserve functionality. Neither replaces the other.

Five Checks Before Cutover

1. Inventory connected apps

2. Review permissions

3. Discover links in critical files

4. Protect links before files move

5. Test what actually works

Turn Migration Into a Controlled Reset

For clarity, I want to repeat that the new app study does not prove that the Microsoft 365 marketplace is packed with dangerous apps. Its much more useful message is that some apps request access that looks unusual when compared with their peers, and that permission information can be difficult to see consistently.

Its conclusions should still be treated with caution. The paper has not yet been peer-reviewed. Its main analysis covered 1,069 apps and its manual assessment involved only eight.

But the principle behind it is solid: Trust should be examined rather than simply inherited.

Intact-Connections

With the correct software, the data connections that users rely on remain intact during migration, preventing downtime and disruption.

Leave a Comment

Please note: All comments are moderated before they are published.





Recent Comments

  • No recent comments available.

Leave a Comment

Please note: All comments are moderated before they are published.