Auditing azure ad app permissions
March 1, 2026
How to see what apps can really do in your tenant
If you’ve ever opened microsoft entra id (azure ad) and clicked through enterprise applications → permissions, you’ve seen the comforting illusion of control: a list of “api permissions” that looks finite, reviewable, and mostly harmless.
In real incidents, that list is rarely the whole story.
The permissions you see (requested…