How to audit third-party OAuth app permissions in Google Workspace. Third-party OAuth applications remain one of the most overlooked security risks in Google Workspace environments. Once authorized, these applications can retain persistent access to user data. In this video, we'll walk through several ways to audit third-party OAuth app permissions in Google Workspace and identify potentially risky integrations. Before we begin, be sure to subscribe to NinjaOne's IT Video Hub and our YouTube channel for more tech content like this. How to audit OAuth apps. Method one: Audit OAuth apps using Google Admin Console. This is the fastest and most accessible way to review OAuth access. Open your browser and go to admin.google.com. Navigate to Security, Access and Data Control, API Controls, App Access Control. Review the list of third-party applications that have access to Google Workspace services and user data. Select an application to review details such as OAuth scopes requested, users who authorized the app. Method two: Export app access details using Google Workspace Reports API. For larger environments, exporting OAuth data allows you to analyze usage trends and identify dormant or risky apps. Option one: Using Google Apps Manager. Before using Google Apps Manager, ensure API access is enabled by navigating to Admin Console, Security, Access and Data Control, API Controls. Next, open Command Prompt as administrator. Type GAM and press Enter. On the first launch, Google Apps Manager will guide you through delegated authentication and API authorization. Then, use this command. This generates data including app name, client ID, authorized user, OAuth scopes, and last used timestamp. This command exports the results to a CSV. Option two: Using PowerShell with Google Workspace Reports API. If you already work heavily in PowerShell, you can query the Reports API directly. Here's a sample request. Replace access_token with a valid OAuth 2.0 access token generated through your Google Cloud project or delegated admin workflow. Make sure the Reports API is enabled in your Google Cloud project and that your API credentials follow least privilege access principles. Method three: Identify and remove risky or inactive OAuth apps. Once you've identified risky or unused apps, remediation should happen immediately. Return to Admin Console, API Controls, App Access Control. Select the third-party application. Review scope usage and user authorization patterns. To block the app, go to Change access, Block access. Blocking the application prevents future authorization and may invalidate existing access tokens, though some cached sessions or refresh tokens may require additional revocation steps. Method four: Log OAuth audit findings in the Windows registry for RMM visibility. To operationalize OAuth audits, you can log audit metadata locally and surface it through your RMM. This is especially useful for MSPs managing multiple tenants. Open PowerShell, then use this script to create a registry key for audit tracking. Then, record the audit date using. Finally, log flagged applications. If you want to verify the registry values, open command prompt, then run. By auditing third-party OAuth permissions regularly, you reduce your attack surface, improve visibility into cloud application access, and strengthen your organization's overall security posture. For more information, check out our official blog post on how to audit third-party OAuth app permissions in Google Workspace, linked in the description below.

How to Audit Third-Party OAuth App Permissions in Google Workspace

Third-party OAuth apps are a growing security blind spot. In this video, we explain how to perform a Google OAuth permission review in Google Workspace to uncover risky or unnecessary app access. You’ll learn where to audit OAuth scopes, how to identify overprivileged apps, and how to safely remove access without breaking workflows. This guide shows how to perform a Google OAuth permission review the right way.

Read the full blog on How to Audit Third-Party OAuth App Permissions in Google Workspace

Never miss a NinjaOne video!